eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details, shutting down the VPN service and to delete the VPN service configuration. This is related to improper access control for all /addons/mh/ pages.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-08-14T20:03:06

Updated: 2024-08-04T21:54:44.866Z

Reserved: 2019-03-06T00:00:00

Link: CVE-2019-9584

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-08-14T21:15:19.250

Modified: 2024-11-21T04:51:54.330

Link: CVE-2019-9584

cve-icon Redhat

No data.