← back
CVE-2019-11891highCWE-266

Incorrect privilege assignment in the app pairing mechanism of the Bosch Smart Home Controller (SHC)

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8epss 0.5%
exploitation probability
0.5%top 56% of all CVEs
observed exploitation
nono source reports it
A potential incorrect privilege assignment vulnerability exists in the app pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in elevated privileges of the adversary's choosing. In order to exploit the vulnerability, the adversary needs physical access to the SHC during the attack.
CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H