CVE-2024-22894

An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.
References
Link Resource
https://github.com/Jaarden/AlphaInnotec-Password-Vulnerability/ Exploit Third Party Advisory
https://github.com/Jaarden/CVE-2024-22894 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:alpha-innotec:heat_pumps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:alpha-innotec:heat_pumps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:alpha-innotec:heat_pumps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:alpha-innotec:heat_pumps:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:novelan:heat_pumps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:novelan:heat_pumps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:novelan:heat_pumps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:novelan:heat_pumps:-:*:*:*:*:*:*:*

History

05 Mar 2024, 21:15

Type Values Removed Values Added
Summary (en) An issue in AIT-Deutschland Alpha Innotec Heatpumps wp2reg-V.3.88.0-9015 and Novelan Heatpumps wp2reg-V.3.88.0-9015, allows remote attackers to execute arbitrary code via the password component in the shadow file. (en) An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.

08 Feb 2024, 16:40

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8
CWE CWE-326
References () https://github.com/Jaarden/AlphaInnotec-Password-Vulnerability/ - () https://github.com/Jaarden/AlphaInnotec-Password-Vulnerability/ - Exploit, Third Party Advisory
References () https://github.com/Jaarden/CVE-2024-22894 - () https://github.com/Jaarden/CVE-2024-22894 - Exploit, Third Party Advisory
CPE cpe:2.3:h:alpha-innotec:heat_pumps:-:*:*:*:*:*:*:*
cpe:2.3:o:alpha-innotec:heat_pumps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:novelan:heat_pumps:-:*:*:*:*:*:*:*
cpe:2.3:o:novelan:heat_pumps_firmware:*:*:*:*:*:*:*:*
First Time Alpha-innotec
Novelan heat Pumps
Novelan heat Pumps Firmware
Alpha-innotec heat Pumps
Novelan
Alpha-innotec heat Pumps Firmware

30 Jan 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-30 10:15

Updated : 2024-03-05 21:15


NVD link : CVE-2024-22894

Mitre link : CVE-2024-22894

CVE.ORG link : CVE-2024-22894


JSON object : View

Products Affected

novelan

  • heat_pumps_firmware
  • heat_pumps

alpha-innotec

  • heat_pumps_firmware
  • heat_pumps
CWE
CWE-326

Inadequate Encryption Strength