• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-11898
2019-10-09
N/A
9.9 CRITICAL
Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The service tool is discontinued with Bosch Access Professional Edition (APE) 3.8.
CVE-2019-11897
2019-10-09
N/A
8.6 HIGH
A Server-Side Request Forgery (SSRF) vulnerability in the backup & restore functionality in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.3.0 allows a remote attacker to forge GET requests to arbitrary URLs. In addition, this could potentially allow an attacker to read sensitive zip files from the local server.
CVE-2019-11896
Bosch, Smart Home Controller, Smart Home Controller Firmware
Divar_ip_5000_firmware, Divar_ip_5000, Smart_home_controller_firmware, Smart_home_controller, Dip_2000_firmware, Dip_2000, Dip_3000_firmware, Dip_3000, Dip_5000_firmware, Dip_5000
2020-10-06
N/A
7.1 HIGH
A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.907 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an app, which requires user interaction.
CVE-2019-11895
Bosch, Smart Home Controller, Smart Home Controller Firmware
Divar_ip_5000_firmware, Divar_ip_5000, Smart_home_controller_firmware, Smart_home_controller, Dip_2000_firmware, Dip_2000, Dip_3000_firmware, Dip_3000, Dip_5000_firmware, Dip_5000
2020-10-06
N/A
5.3 MEDIUM
A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a successful denial of service of the SHC and connected sensors and actuators. In order to exploit the vulnerability, the adversary needs to have successfully paired an app or service, which requires user interaction.
CVE-2019-11894
Bosch, Smart Home Controller, Smart Home Controller Firmware
Divar_ip_5000_firmware, Divar_ip_5000, Smart_home_controller_firmware, Smart_home_controller, Dip_2000_firmware, Dip_2000, Dip_3000_firmware, Dip_3000, Dip_5000_firmware, Dip_5000
2020-10-06
N/A
5.7 MEDIUM
A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in unauthorized download of a backup. In order to exploit the vulnerability, the adversary needs to download the backup directly after a backup triggered by a legitimate user has been completed.
CVE-2019-11893
Bosch, Smart Home Controller, Smart Home Controller Firmware
Divar_ip_5000_firmware, Divar_ip_5000, Smart_home_controller_firmware, Smart_home_controller, Dip_2000_firmware, Dip_2000, Dip_3000_firmware, Dip_3000, Dip_5000_firmware, Dip_5000
2020-10-06
N/A
8 HIGH
A potential incorrect privilege assignment vulnerability exists in the app permission update API of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an app with restricted permissions, which required user interaction.
CVE-2019-11892
Bosch, Smart Home Controller, Smart Home Controller Firmware
Divar_ip_5000_firmware, Divar_ip_5000, Smart_home_controller_firmware, Smart_home_controller, Dip_2000_firmware, Dip_2000, Dip_3000_firmware, Dip_3000, Dip_5000_firmware, Dip_5000
2020-10-06
N/A
8 HIGH
A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in reading or modification of the SHC's configuration or triggering and restoring backups. In order to exploit the vulnerability, the adversary needs to have successfully paired an app or service, which requires user interaction.
CVE-2019-11891
Bosch, Smart Home Controller, Smart Home Controller Firmware
Divar_ip_5000_firmware, Divar_ip_5000, Smart_home_controller_firmware, Smart_home_controller, Dip_2000_firmware, Dip_2000, Dip_3000_firmware, Dip_3000, Dip_5000_firmware, Dip_5000
2020-10-06
N/A
8 HIGH
A potential incorrect privilege assignment vulnerability exists in the app pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in elevated privileges of the adversary's choosing. In order to exploit the vulnerability, the adversary needs physical access to the SHC during the attack.
CVE-2019-11890
Bravia Firmware, Sony
Photo_sharing_plus, Kdl-50w800c, Kdl-50w805c, Kdl-50w807c, Kdl-50w809c, Kdl-50w820c, Kdl-55w800c, Kdl-55w805c, Kdl-65w850c, Kdl-65w855c
2020-08-24
N/A
7.5 HIGH
Sony Bravia Smart TV devices allow remote attackers to cause a denial of service (device hang or reboot) via a SYN flood attack over a wired or Wi-Fi LAN.
CVE-2019-1189
2020-01-24
N/A
N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.
« Previous 1 … 6,428 6,429 6,430 6,431 6,432 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE