CVE-2019-11601 is a directory traversal vulnerability affecting Bosch IoT Gateway Software prior to version 9.2.0 and ProSyst mBS SDK prior to 8.2.6. This flaw allows unauthenticated remote attackers to write or delete arbitrary files on the affected system through the remote access backup and restore functionality. With a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network with low attack complexity, leading to high impact on integrity and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.2.0CPE matchmatch criteria | cpe:2.3:a:bosch:iot_gateway_software:*:*:*:*:*:*:*:* | ||
< 8.2.6CPE matchmatch criteria | cpe:2.3:a:bosch:prosyst_mbs_sdk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple Vulnerabilities in ProSyst mBS SDK and Bosch IoT Gateway Software
Aug 19, 2019Multiple Vulnerabilities in ProSyst mBS SDK and Bosch IoT Gateway Software
Aug 19, 2019Multiple Vulnerabilities in ProSyst mBS SDK and Bosch IoT Gateway Software
Aug 19, 2019Multiple Vulnerabilities in ProSyst mBS SDK and Bosch IoT Gateway Software
Aug 19, 2019Multiple Vulnerabilities in ProSyst mBS SDK and Bosch IoT Gateway Software
Aug 19, 2019Multiple Vulnerabilities in Bosch Smart Home Controller
May 29, 2019Multiple Vulnerabilities in Bosch Smart Home Controller
May 29, 2019Multiple Vulnerabilities in Bosch Smart Home Controller
May 29, 2019Multiple Vulnerabilities in Bosch Smart Home Controller
May 29, 2019Multiple Vulnerabilities in Bosch Smart Home Controller
May 29, 2019