PT-2019-12553 · Bosch · Bosch Smart Home Controller
Philip Kazmeier
·
Published
2019-05-29
·
Updated
2020-10-06
·
CVE-2019-11896
CVSS v3.1
7.1
High
| Vector | AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Bosch Smart Home Controller versions prior to 9.8.907
Description
A potential incorrect privilege assignment issue exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller. This issue may result in a restricted app obtaining default app permissions. To exploit this issue, an adversary needs to have successfully paired an app, which requires user interaction.
Recommendations
For versions prior to 9.8.907, update to version 9.8.907 or later to resolve the issue.
Fix
Improper Access Control
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bosch Smart Home Controller