ZeroHour

CVE-2019-11897

CVSS 3.0
8.6 high
EPSS
2%p77
Published
()
Modified
Description

A Server-Side Request Forgery (SSRF) vulnerability in the backup & restore functionality in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.3.0 allows a remote attacker to forge GET requests to arbitrary URLs. In addition, this could potentially allow an attacker to read sensitive zip files from the local server.

Vendors
bosch
Products
iot gateway software, prosyst mbs sdk
Weakness
CWE-918
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.