Show filters
70 Total Results
Displaying 61-70 of 70
Sort by:
Attacker Value
Unknown
CVE-2020-6781
Disclosure Date: August 25, 2020 (last updated February 22, 2025)
Improper certificate validation for certain connections in the Bosch Smart Home System App for iOS prior to version 9.17.1 potentially allows to intercept video contents by performing a man-in-the-middle attack.
0
Attacker Value
Unknown
Incorrect pviilege assignment in the 3rd party pairing mechanism of the Bosch S…
Disclosure Date: May 29, 2019 (last updated November 27, 2024)
A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.907 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an app, which requires user interaction.
0
Attacker Value
Unknown
Improper access control in the backup mechanism of the Bosch Smart Home Control…
Disclosure Date: May 29, 2019 (last updated November 27, 2024)
A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in unauthorized download of a backup. In order to exploit the vulnerability, the adversary needs to download the backup directly after a backup triggered by a legitimate user has been completed.
0
Attacker Value
Unknown
Improper access control in the JSON-RPC interface of the Bosch Smart Home Contr…
Disclosure Date: May 29, 2019 (last updated November 27, 2024)
A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a successful denial of service of the SHC and connected sensors and actuators. In order to exploit the vulnerability, the adversary needs to have successfully paired an app or service, which requires user interaction.
0
Attacker Value
Unknown
Improper access control in the JSON-RPC interface of the Bosch Smart Home Contr…
Disclosure Date: May 29, 2019 (last updated November 27, 2024)
A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in reading or modification of the SHC's configuration or triggering and restoring backups. In order to exploit the vulnerability, the adversary needs to have successfully paired an app or service, which requires user interaction.
0
Attacker Value
Unknown
Incorrect privilege assignment in the app pairing mechanism of the Bosch Smart …
Disclosure Date: May 29, 2019 (last updated November 27, 2024)
A potential incorrect privilege assignment vulnerability exists in the app pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in elevated privileges of the adversary's choosing. In order to exploit the vulnerability, the adversary needs physical access to the SHC during the attack.
0
Attacker Value
Unknown
Incorrect privilege assignment in the app permission update API of the Bosch Sm…
Disclosure Date: May 29, 2019 (last updated November 27, 2024)
A potential incorrect privilege assignment vulnerability exists in the app permission update API of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an app with restricted permissions, which required user interaction.
0
Attacker Value
Unknown
CVE-2019-9659
Disclosure Date: March 11, 2019 (last updated November 27, 2024)
The Chuango 433 MHz burglar-alarm product line uses static codes in the RF remote control, allowing an attacker to arm, disarm, or trigger the alarm remotely via replay attacks, as demonstrated by Chuango branded products, and non-Chuango branded products such as the Eminent EM8617 OV2 Wifi Alarm System.
0
Attacker Value
Unknown
CVE-2018-9162
Disclosure Date: March 31, 2018 (last updated November 26, 2024)
Contec Smart Home 4.15 devices do not require authentication for new_user.php, edit_user.php, delete_user.php, and user.php, as demonstrated by changing the admin password and then obtaining control over doors.
0
Attacker Value
Unknown
CVE-2014-4892
Disclosure Date: October 21, 2014 (last updated October 05, 2023)
The uControl Smart Home Automation (aka de.ucontrol) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0