Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ghfv-mcwg-v5xw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

A potential incorrect privilege assignment vulnerability exists in the app pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in elevated privileges of the adversary's choosing. In order to exploit the vulnerability, the adversary needs physical access to the SHC during the attack.

A potential incorrect privilege assignment vulnerability exists in the app pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in elevated privileges of the adversary's choosing. In order to exploit the vulnerability, the adversary needs physical access to the SHC during the attack.

EPSS

Процентиль: 30%
0.0011
Низкий

8 High

CVSS3

Дефекты

CWE-266
CWE-269

Связанные уязвимости

CVSS3: 8
nvd
больше 6 лет назад

A potential incorrect privilege assignment vulnerability exists in the app pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in elevated privileges of the adversary's choosing. In order to exploit the vulnerability, the adversary needs physical access to the SHC during the attack.

EPSS

Процентиль: 30%
0.0011
Низкий

8 High

CVSS3

Дефекты

CWE-266
CWE-269