Description
Directory Traversal / Arbitrary File Read in User.getLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to read the first line of an arbitrary file on the CCU2's filesystem. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.
Published: 2018-02-22
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-19030 Directory Traversal / Arbitrary File Read in User.getLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to read the first line of an arbitrary file on the CCU2's filesystem. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.
History

No history.

Subscriptions

Eq-3 Homematic Central Control Unit Ccu2 Homematic Central Control Unit Ccu2 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T06:24:11.892Z

Reserved: 2018-02-21T00:00:00.000Z

Link: CVE-2018-7296

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-02-22T19:29:04.530

Modified: 2024-11-21T04:11:57.297

Link: CVE-2018-7296

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses