PT-2019-12550 · Bosch · Bosch Smart Home Controller

Philip Kazmeier

·

Published

2019-05-29

·

Updated

2020-10-06

·

CVE-2019-11893

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bosch Smart Home Controller (SHC) versions prior to 9.8.905
Description A potential incorrect privilege assignment issue exists in the app permission update API, which may allow a restricted app to obtain default app permissions. To exploit this, an adversary must first successfully pair an app with restricted permissions, requiring user interaction.
Recommendations For versions prior to 9.8.905, update to version 9.8.905 or later to resolve the issue. As a temporary workaround, consider restricting app pairing to minimize the risk of exploitation.

Fix

Improper Privilege Management

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11893

Affected Products

Bosch Smart Home Controller