Vulnerability Details CVE-2019-9585
eQ-3 Homematic CCU2 prior to 2.47.10 and CCU3 prior to 3.47.10 JSON API has Improper Access Control for Interface.***Metadata related operations, resulting in the ability to read, set and deletion of Metadata.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 62.4%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2019-9585
-
cpe:2.3:h:eq-3:homematic_ccu2:-
-
cpe:2.3:h:eq-3:homematic_ccu3:-
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:-
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:1.2.0
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.11.6
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.11.9
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.13.7
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.15.2
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.15.5
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.17.14
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.17.15
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.17.16
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.19.9
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.21.10
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.24.20
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.25.12
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.25.14
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.25.15
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.27.7
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.27.8
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.29.18
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.29.23
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.3.0
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.3.17
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.3.18
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.31.23
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.31.25
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.35.16
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.41.5
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.41.8
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.41.9
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.45.6
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.45.7
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.5.4
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.7.16
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.7.17
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.7.8
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.9.10
-
cpe:2.3:o:eq-3:homematic_ccu2_firmware:2.9.12
-
cpe:2.3:o:eq-3:homematic_ccu3_firmware:-
-
cpe:2.3:o:eq-3:homematic_ccu3_firmware:1.2.0
-
cpe:2.3:o:eq-3:homematic_ccu3_firmware:2.3.0
-
cpe:2.3:o:eq-3:homematic_ccu3_firmware:3.14.11
-
cpe:2.3:o:eq-3:homematic_ccu3_firmware:3.41.11
-
cpe:2.3:o:eq-3:homematic_ccu3_firmware:3.43.16
-
cpe:2.3:o:eq-3:homematic_ccu3_firmware:3.45.5
-
cpe:2.3:o:eq-3:homematic_ccu3_firmware:3.45.7