CVE-2019-11603: Path traversal in ProSyst mBS SDK and Bosch IoT Gateway Software
Published Aug 21, 2019
·Updated
A HTTP Traversal Attack in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.0.2 allows remote attackers to read files outside the http root.
Affected Software
2 affected components
Bosch IoT Gateway Software<9.0.2
Bosch ProSyst mBS SDK<8.2.6
Event History
Aug 21, 2019
CVE Published
via MITRE·07:29 PM
Data Sourced
via MITRE·07:29 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2019-11603?
CVE-2019-11603 has a medium severity level due to the potential for unauthorized file access.
2
How do I fix CVE-2019-11603?
To fix CVE-2019-11603, upgrade to Bosch IoT Gateway Software version 9.0.2 or ProSyst mBS SDK version 8.2.6 or later.
3
What systems are affected by CVE-2019-11603?
CVE-2019-11603 affects earlier versions of Bosch IoT Gateway Software before 9.0.2 and ProSyst mBS SDK before 8.2.6.
4
What type of attack does CVE-2019-11603 involve?
CVE-2019-11603 involves a HTTP Traversal Attack that allows remote attackers to read files outside the HTTP root.
5
Can CVE-2019-11603 be exploited remotely?
Yes, CVE-2019-11603 can be exploited remotely by attackers to access sensitive files.