eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details, shutting down the VPN service and to delete the VPN service configuration. This is related to improper access control for all /addons/mh/ pages.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-08-14T20:03:06

Updated: 2019-08-14T20:03:06

Reserved: 2019-03-06T00:00:00


Link: CVE-2019-9584

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-08-14T21:15:19.250

Modified: 2020-08-24T17:37:01.140


Link: CVE-2019-9584

JSON object: View

cve-icon Redhat Information

No data.

CWE