CVE-2024-22894

An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.
References
Link Resource
https://github.com/Jaarden/AlphaInnotec-Password-Vulnerability/ Exploit Third Party Advisory
https://github.com/Jaarden/CVE-2024-22894 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:alpha-innotec:heat_pumps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:alpha-innotec:heat_pumps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:alpha-innotec:heat_pumps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:alpha-innotec:heat_pumps:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:novelan:heat_pumps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:novelan:heat_pumps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:novelan:heat_pumps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:novelan:heat_pumps:-:*:*:*:*:*:*:*

History

05 Mar 2024, 21:15

Type Values Removed Values Added
Summary (en) An issue in AIT-Deutschland Alpha Innotec Heatpumps wp2reg-V.3.88.0-9015 and Novelan Heatpumps wp2reg-V.3.88.0-9015, allows remote attackers to execute arbitrary code via the password component in the shadow file. (en) An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.

08 Feb 2024, 16:40

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8
References () https://github.com/Jaarden/AlphaInnotec-Password-Vulnerability/ - () https://github.com/Jaarden/AlphaInnotec-Password-Vulnerability/ - Exploit, Third Party Advisory
References () https://github.com/Jaarden/CVE-2024-22894 - () https://github.com/Jaarden/CVE-2024-22894 - Exploit, Third Party Advisory
CPE cpe:2.3:h:novelan:heat_pumps:-:*:*:*:*:*:*:*
cpe:2.3:o:alpha-innotec:heat_pumps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:novelan:heat_pumps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:alpha-innotec:heat_pumps:-:*:*:*:*:*:*:*
First Time Alpha-innotec heat Pumps
Novelan heat Pumps
Alpha-innotec heat Pumps Firmware
Novelan heat Pumps Firmware
Alpha-innotec
Novelan
CWE CWE-326

30 Jan 2024, 14:18

Type Values Removed Values Added
Summary
  • (es) Un problema en AIT-Deutschland Alpha Innotec Heatpumps wp2reg-V.3.88.0-9015 y Novelan Heatpumps wp2reg-V.3.88.0-9015 permite a atacantes remotos ejecutar código arbitrario a través del componente de contraseña en el archivo sombra.

30 Jan 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-30 10:15

Updated : 2024-03-05 21:15


NVD link : CVE-2024-22894

Mitre link : CVE-2024-22894

CVE.ORG link : CVE-2024-22894


JSON object : View

Products Affected

novelan

  • heat_pumps_firmware
  • heat_pumps

alpha-innotec

  • heat_pumps
  • heat_pumps_firmware
CWE
CWE-326

Inadequate Encryption Strength