First published: Wed Aug 21 2019(Updated: )
A directory traversal vulnerability in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to write or delete files at any location.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bosch IoT Gateway Software | <9.2.0 | |
Bosch Prosyst Mbs SDK | <8.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11601 has a high severity rating due to its potential to allow unauthorized file manipulation by remote attackers.
To remediate CVE-2019-11601, upgrade to Bosch IoT Gateway Software version 9.2.0 or ProSyst mBS SDK version 8.2.6 or later.
CVE-2019-11601 affects Bosch IoT Gateway Software prior to version 9.2.0 and ProSyst mBS SDK prior to version 8.2.6.
CVE-2019-11601 is classified as a directory traversal vulnerability.
Yes, CVE-2019-11601 can be exploited remotely by attackers to write or delete files at any location.