ZeroHour

CVE-2024-22894

PoC ×2
CVSS 3.1
6.8 medium
EPSS
<1%p52
Published
()
Modified
Description

An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.

Vendors
alpha-innotecnovelan
Products
heat pumps firmware
Weakness
CWE-326
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.