← back
CVE-2019-11893mediumCWE-266

Incorrect privilege assignment in the app permission update API of the Bosch Smart Home Controller (SHC)

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.5epss 0.4%
exploitation probability
0.4%top 62% of all CVEs
observed exploitation
nono source reports it
A potential incorrect privilege assignment vulnerability exists in the app permission update API of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an app with restricted permissions, which required user interaction.
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L