CVE-2019-11895
Summary
| CVE | CVE-2019-11895 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-29 21:29:00 UTC |
| Updated | 2020-10-06 14:47:00 UTC |
| Description | A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a successful denial of service of the SHC and connected sensors and actuators. In order to exploit the vulnerability, the adversary needs to have successfully paired an app or service, which requires user interaction. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Bosch | Smart Home Controller | All | All | All | All |
| Hardware | Bosch | Smart Home Controller | All | All | All | All |
| Operating System | Bosch | Smart Home Controller Firmware | All | All | All | All |
| Operating System | Bosch | Smart Home Controller Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| BOSCH-SA-662084 | Bosch PSIRT | CONFIRM | psirt.bosch.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Philip Kazmeier
There are currently no legacy QID mappings associated with this CVE.