Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qfhr-mxhr-cf29

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.907 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an app, which requires user interaction.

A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.907 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an app, which requires user interaction.

EPSS

Процентиль: 37%
0.00162
Низкий

7.1 High

CVSS3

Дефекты

CWE-269
CWE-284

Связанные уязвимости

CVSS3: 7.1
nvd
больше 6 лет назад

A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.907 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an app, which requires user interaction.

EPSS

Процентиль: 37%
0.00162
Низкий

7.1 High

CVSS3

Дефекты

CWE-269
CWE-284