CVE-2024-22894
MEDIUMAlpha Innotec and Novelan Heat Pumps Firmware < 2.88.3 - Inadequate Encryption Strength in Password Component
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-22894. PoCs published by Jaarden.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2024-22894, a vulnerability in Alpha Innotec and Novelan heatpumps where a hardcoded 3DES-encrypted root password ('eschi') is exposed in the firmware. The writeup includes steps to exploit the vulnerability via SSH, affected versions, and a timeline of responsible disclosure.
Description
An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2024-22894, a vulnerability in Alpha Innotec and Novelan heatpumps where a hardcoded 3DES-encrypted root password ('eschi') is exposed in the firmware. The writeup includes steps to exploit the vulnerability via SSH, affected versions, and a timeline of responsible disclosure.
References (2)
Scores
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H