CVE-2019-11894 is an improper access control vulnerability in the backup mechanism of Bosch Smart Home Controllers (SHC) prior to version 9.8.905, allowing unauthorized backup downloads. An attacker on the local network could exploit this by timing a download immediately after a legitimate user initiates a backup. Rated Medium (CVSS 5.7), the vulnerability has high confidentiality impact but requires user interaction and network proximity. There is no evidence of active exploitation, public exploit code, or significant community discussion for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.8.905CPE matchmatch criteria | cpe:2.3:o:bosch:smart_home_controller_firmware:*:*:*:*:*:*:*:* | ||
< 9.8.905CPE match | cpe:2.3:a:bosch:smart_home_controller:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple Vulnerabilities in Bosch Smart Home Controller
May 29, 2019Multiple Vulnerabilities in Bosch Smart Home Controller
May 29, 2019Multiple Vulnerabilities in Bosch Smart Home Controller
May 29, 2019Multiple Vulnerabilities in Bosch Smart Home Controller
May 29, 2019Multiple Vulnerabilities in Bosch Smart Home Controller
May 29, 2019