First published: Wed Sep 16 2020(Updated: )
Improper certificate validation for certain connections in the Bosch Smart Home System App for iOS prior to version 9.17.1 potentially allows to intercept video contents by performing a man-in-the-middle attack.
Credit: psirt@bosch.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bosch Smart Home | <9.17.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6781 is a vulnerability in the Bosch Smart Home System App for iOS that allows for interception of video contents through a man-in-the-middle attack.
CVE-2020-6781 has a severity rating of 7.4 (High).
CVE-2020-6781 affects versions of the Bosch Smart Home System App for iOS prior to 9.17.1 and allows for improper certificate validation, potentially enabling interception of video contents.
A man-in-the-middle attack can exploit CVE-2020-6781 by intercepting certain connections in the Bosch Smart Home System App for iOS and capturing video contents.
To fix CVE-2020-6781, update the Bosch Smart Home System App for iOS to version 9.17.1 or higher.