CVE-2019-11896: Incorrect pviilege assignment in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC)
A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.907 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an app, which requires user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-11896?
CVE-2019-11896 has a severity rating that indicates a potential for privilege escalation in the Bosch Smart Home Controller.
How do I fix CVE-2019-11896?
To fix CVE-2019-11896, upgrade the Bosch Smart Home Controller firmware to version 9.8.907 or later.
What systems are affected by CVE-2019-11896?
CVE-2019-11896 affects Bosch Smart Home Controller firmware versions prior to 9.8.907.
What is the vulnerability type of CVE-2019-11896?
CVE-2019-11896 is classified as an incorrect privilege assignment vulnerability.
Can CVE-2019-11896 be exploited remotely?
Exploitation of CVE-2019-11896 requires an adversary to access the pairing mechanism locally.