CVE-2024-22894

An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.
References
Link Resource
https://github.com/Jaarden/AlphaInnotec-Password-Vulnerability/ Exploit Third Party Advisory
https://github.com/Jaarden/CVE-2024-22894 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:alpha-innotec:heat_pumps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:alpha-innotec:heat_pumps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:alpha-innotec:heat_pumps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:alpha-innotec:heat_pumps:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:novelan:heat_pumps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:novelan:heat_pumps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:novelan:heat_pumps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:novelan:heat_pumps:-:*:*:*:*:*:*:*

History

05 Mar 2024, 21:15

Type Values Removed Values Added
Summary (en) An issue in AIT-Deutschland Alpha Innotec Heatpumps wp2reg-V.3.88.0-9015 and Novelan Heatpumps wp2reg-V.3.88.0-9015, allows remote attackers to execute arbitrary code via the password component in the shadow file. (en) An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.

08 Feb 2024, 16:40

Type Values Removed Values Added
References () https://github.com/Jaarden/AlphaInnotec-Password-Vulnerability/ - () https://github.com/Jaarden/AlphaInnotec-Password-Vulnerability/ - Exploit, Third Party Advisory
References () https://github.com/Jaarden/CVE-2024-22894 - () https://github.com/Jaarden/CVE-2024-22894 - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8
CWE CWE-326
First Time Novelan heat Pumps
Novelan heat Pumps Firmware
Alpha-innotec heat Pumps
Alpha-innotec
Alpha-innotec heat Pumps Firmware
Novelan
CPE cpe:2.3:h:novelan:heat_pumps:-:*:*:*:*:*:*:*
cpe:2.3:o:alpha-innotec:heat_pumps_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:alpha-innotec:heat_pumps:-:*:*:*:*:*:*:*
cpe:2.3:o:novelan:heat_pumps_firmware:*:*:*:*:*:*:*:*

30 Jan 2024, 14:18

Type Values Removed Values Added
Summary
  • (es) Un problema en AIT-Deutschland Alpha Innotec Heatpumps wp2reg-V.3.88.0-9015 y Novelan Heatpumps wp2reg-V.3.88.0-9015 permite a atacantes remotos ejecutar código arbitrario a través del componente de contraseña en el archivo sombra.

30 Jan 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-30 10:15

Updated : 2024-03-05 21:15


NVD link : CVE-2024-22894

Mitre link : CVE-2024-22894

CVE.ORG link : CVE-2024-22894


JSON object : View

Products Affected

alpha-innotec

  • heat_pumps
  • heat_pumps_firmware

novelan

  • heat_pumps_firmware
  • heat_pumps
CWE
CWE-326

Inadequate Encryption Strength