Description
A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.907 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an app, which requires user interaction.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-3554 | A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.907 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an app, which requires user interaction. |
References
| Link | Providers |
|---|---|
| https://psirt.bosch.com/Advisory/BOSCH-SA-662084.html |
|
History
No history.
Status: PUBLISHED
Assigner: bosch
Published:
Updated: 2024-09-16T19:24:49.342Z
Reserved: 2019-05-13T00:00:00.000Z
Link: CVE-2019-11896
No data.
Status : Modified
Published: 2019-05-29T21:29:02.153
Modified: 2024-11-21T04:21:58.757
Link: CVE-2019-11896
No data.
OpenCVE Enrichment
No data.
EUVD