eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details, shutting down the VPN service and to delete the VPN service configuration. This is related to improper access control for all /addons/mh/ pages.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-08-14T20:03:06

Updated: 2024-08-04T21:54:44.866Z

Reserved: 2019-03-06T00:00:00

Link: CVE-2019-9584

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-08-14T21:15:19.250

Modified: 2020-08-24T17:37:01.140

Link: CVE-2019-9584

cve-icon Redhat

No data.