Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-422w-959p-3whv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

A potential incorrect privilege assignment vulnerability exists in the app permission update API of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an app with restricted permissions, which required user interaction.

A potential incorrect privilege assignment vulnerability exists in the app permission update API of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an app with restricted permissions, which required user interaction.

EPSS

Процентиль: 17%
0.00054
Низкий

8 High

CVSS3

Дефекты

CWE-266
CWE-269

Связанные уязвимости

CVSS3: 8
nvd
больше 6 лет назад

A potential incorrect privilege assignment vulnerability exists in the app permission update API of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an app with restricted permissions, which required user interaction.

EPSS

Процентиль: 17%
0.00054
Низкий

8 High

CVSS3

Дефекты

CWE-266
CWE-269