CVE-2024-22894
Published Jan 30, 2024
Last updated 3 months ago
Overview
- Description
- An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 6.8
- Impact score
- 5.9
- Exploitability score
- 0.9
- Vector string
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- MEDIUM
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:alpha-innotec:heat_pumps_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0748DE3E-9C10-4E55-9CE2-2FC142C70AA2", "versionEndExcluding": "2.88.3" }, { "criteria": "cpe:2.3:o:alpha-innotec:heat_pumps_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1AB21F68-A56D-44F4-9E8F-35FE4F633276", "versionEndExcluding": "3.89.0", "versionStartIncluding": "3.0.0" }, { "criteria": "cpe:2.3:o:alpha-innotec:heat_pumps_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AF001062-843A-48C0-BBB1-39EF0169FF04", "versionEndExcluding": "4.81.3", "versionStartIncluding": "4.0.0" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:alpha-innotec:heat_pumps:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D87D8C1B-B1F7-4FC4-B857-5BEEA2A8C74F" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:novelan:heat_pumps_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DDDB466A-0CC1-4C7B-914A-BEC7A3AFA835", "versionEndExcluding": "2.88.3" }, { "criteria": "cpe:2.3:o:novelan:heat_pumps_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F60C4875-FB5D-41A8-8FCC-EEF050BDE9A3", "versionEndExcluding": "3.89.0", "versionStartIncluding": "3.0.0" }, { "criteria": "cpe:2.3:o:novelan:heat_pumps_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9DFEEE56-A799-4CCD-A33B-83A0177FCF71", "versionEndExcluding": "4.81.3", "versionStartIncluding": "4.0.0" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:novelan:heat_pumps:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "80BCEF4F-B08E-4776-94D9-EABA4F3BE412" } ], "operator": "OR" } ], "operator": "AND" } ]