Show filters
1 Total Results
Displaying 1-1 of 1
Sort by:
Attacker Value
Unknown

Incorrect privilege assignment in the app permission update API of the Bosch Sm…

Disclosure Date: May 29, 2019 (last updated November 27, 2024)
A potential incorrect privilege assignment vulnerability exists in the app permission update API of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an app with restricted permissions, which required user interaction.