PT-2019-12555 · Bosch · Bosch Access Professional Edition

Oleksii Orekhov

·

Published

2019-09-12

·

Updated

2019-10-09

·

CVE-2019-11898

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bosch Access Professional Edition (APE) versions prior to 3.8
Description The issue allows unauthorized APE administration privileges to be obtained through reverse engineering of a discontinued APE service tool.
Recommendations For versions prior to 3.8, update to version 3.8 or later to resolve the issue.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11898

Affected Products

Bosch Access Professional Edition