Improper access control in the backup mechanism of the Bosch Smart Home Controller (SHC)
Vulnerability Description
A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in unauthorized download of a backup. In order to exploit the vulnerability, the adversary needs to download the backup directly after a backup triggered by a legitimate user has been completed.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-11894
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Philip Kazmeier
More from Bosch
View All →Affected Vendor
Bosch
View all reports →