CVE-2019-11897 is a Server-Side Request Forgery (SSRF) vulnerability affecting Bosch IoT Gateway Software prior to 9.3.0 and ProSyst mBS SDK prior to 8.2.6, specifically within their backup and restore functionality. This high-severity vulnerability (CVSS 8.6) allows an unauthenticated remote attacker to forge GET requests to arbitrary URLs, potentially leading to the disclosure of sensitive zip files from the local server. While the EPSS score is low, indicating a low likelihood of exploitation, there is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.3.0CPE matchmatch criteria | cpe:2.3:a:bosch:iot_gateway_software:*:*:*:*:*:*:*:* | ||
< 8.2.6CPE matchmatch criteria | cpe:2.3:a:bosch:prosyst_mbs_sdk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple Vulnerabilities in ProSyst mBS SDK and Bosch IoT Gateway Software
Aug 19, 2019Multiple Vulnerabilities in ProSyst mBS SDK and Bosch IoT Gateway Software
Aug 19, 2019Multiple Vulnerabilities in ProSyst mBS SDK and Bosch IoT Gateway Software
Aug 19, 2019Multiple Vulnerabilities in ProSyst mBS SDK and Bosch IoT Gateway Software
Aug 19, 2019Multiple Vulnerabilities in ProSyst mBS SDK and Bosch IoT Gateway Software
Aug 19, 2019Multiple Vulnerabilities in Bosch Smart Home Controller
May 29, 2019Multiple Vulnerabilities in Bosch Smart Home Controller
May 29, 2019Multiple Vulnerabilities in Bosch Smart Home Controller
May 29, 2019Multiple Vulnerabilities in Bosch Smart Home Controller
May 29, 2019Multiple Vulnerabilities in Bosch Smart Home Controller
May 29, 2019