Vulnerability Details CVE-2019-18938
eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the E-Mail AddOn through 1.6.8.c installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the save.cgi script for payload upload and the testtcl.cgi script for its execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.301
EPSS Ranking 96.4%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2019-18938
-
cpe:2.3:a:hm_email_project:hm_email:1.6.0
-
cpe:2.3:a:hm_email_project:hm_email:1.6.2
-
cpe:2.3:a:hm_email_project:hm_email:1.6.3
-
cpe:2.3:a:hm_email_project:hm_email:1.6.4
-
cpe:2.3:a:hm_email_project:hm_email:1.6.5
-
cpe:2.3:a:hm_email_project:hm_email:1.6.6
-
cpe:2.3:a:hm_email_project:hm_email:1.6.7
-
cpe:2.3:a:hm_email_project:hm_email:1.6.7a
-
cpe:2.3:a:hm_email_project:hm_email:1.6.7b
-
cpe:2.3:a:hm_email_project:hm_email:1.6.7c
-
cpe:2.3:a:hm_email_project:hm_email:1.6.8
-
cpe:2.3:a:hm_email_project:hm_email:1.6.8a
-
cpe:2.3:a:hm_email_project:hm_email:1.6.8b
-
cpe:2.3:a:hm_email_project:hm_email:1.6.8c
-
cpe:2.3:h:eq-3:homematic_ccu2:-
-
cpe:2.3:h:eq-3:homematic_ccu3:-
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.24.20
-
cpe:2.3:o:eq-3:homematic_ccu3_firmware:3.47.18