CVE-2019-11891
Summary
| CVE | CVE-2019-11891 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-29 20:29:00 UTC |
| Updated | 2020-10-06 14:38:00 UTC |
| Description | A potential incorrect privilege assignment vulnerability exists in the app pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in elevated privileges of the adversary's choosing. In order to exploit the vulnerability, the adversary needs physical access to the SHC during the attack. |
Risk And Classification
Problem Types: CWE-269
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Bosch | Smart Home Controller | - | All | All | All |
| Hardware | Bosch | Smart Home Controller | - | All | All | All |
| Operating System | Bosch | Smart Home Controller Firmware | All | All | All | All |
| Operating System | Bosch | Smart Home Controller Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| BOSCH-SA-662084 | Bosch PSIRT | CONFIRM | psirt.bosch.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Philip Kazmeier
There are currently no legacy QID mappings associated with this CVE.