Vulnerability Description
A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in unauthorized download of a backup. In order to exploit the vulnerability, the adversary needs to download the backup directly after a backup triggered by a legitimate user has been completed.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bosch | Smart Home Controller Firmware | < 9.8.905 |
| Bosch | Smart Home Controller | - |
Related Weaknesses (CWE)
References
- https://psirt.bosch.com/Advisory/BOSCH-SA-662084.htmlVendor Advisory
- https://psirt.bosch.com/Advisory/BOSCH-SA-662084.htmlVendor Advisory
FAQ
What is CVE-2019-11894?
CVE-2019-11894 is a vulnerability with a CVSS score of 5.7 (MEDIUM). A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in unauthorized download of a backup. In order ...
How severe is CVE-2019-11894?
CVE-2019-11894 has been rated MEDIUM with a CVSS base score of 5.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-11894?
Check the references section above for vendor advisories and patch information. Affected products include: Bosch Smart Home Controller Firmware, Bosch Smart Home Controller.