First published: Wed Aug 21 2019(Updated: )
A HTTP Traversal Attack in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.0.2 allows remote attackers to read files outside the http root.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bosch IoT Gateway Software | <9.0.2 | |
Bosch Prosyst Mbs SDK | <8.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11603 has a medium severity level due to the potential for unauthorized file access.
To fix CVE-2019-11603, upgrade to Bosch IoT Gateway Software version 9.0.2 or ProSyst mBS SDK version 8.2.6 or later.
CVE-2019-11603 affects earlier versions of Bosch IoT Gateway Software before 9.0.2 and ProSyst mBS SDK before 8.2.6.
CVE-2019-11603 involves a HTTP Traversal Attack that allows remote attackers to read files outside the HTTP root.
Yes, CVE-2019-11603 can be exploited remotely by attackers to access sensitive files.