Description
A Server-Side Request Forgery (SSRF) vulnerability in the backup & restore functionality in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.3.0 allows a remote attacker to forge GET requests to arbitrary URLs. In addition, this could potentially allow an attacker to read sensitive zip files from the local server.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-3555 | A Server-Side Request Forgery (SSRF) vulnerability in the backup & restore functionality in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.3.0 allows a remote attacker to forge GET requests to arbitrary URLs. In addition, this could potentially allow an attacker to read sensitive zip files from the local server. |
References
| Link | Providers |
|---|---|
| https://psirt.bosch.com/Advisory/BOSCH-SA-562575.html |
|
History
No history.
Status: PUBLISHED
Assigner: bosch
Published:
Updated: 2024-09-17T03:55:02.429Z
Reserved: 2019-05-13T00:00:00.000Z
Link: CVE-2019-11897
No data.
Status : Modified
Published: 2019-08-21T18:15:13.273
Modified: 2024-11-21T04:21:58.873
Link: CVE-2019-11897
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD