CVE-2019-11894
Status: ModifiedMedium (5.7)—
A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in unauthorized download of a backup. In order to exploit the vulnerability, the adversary needs to download the backup directly after a backup triggered by a legitimate user has been completed.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Base score: 5.7
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.50%
- Percentile among all scored CVEs: 41
- Score date: 10/4/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-284
- NVD-CWE-Other
References
Raw JSON (NVD)
Show
{
"id": "CVE-2019-11894",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.9,
"accessVector": "ADJACENT_NETWORK",
"vectorString": "AV:A/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 5.5,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "psirt@bosch.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 5.7,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.1
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.7,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.1
}
]
},
"affected": [
{
"source": "psirt@bosch.com",
"affectedData": [
{
"vendor": "Bosch",
"product": "Smart Home Controller",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "9.8.905",
"versionType": "custom"
}
]
}
]
}
],
"published": "2019-05-29T21:29:02.073",
"references": [
{
"url": "https://psirt.bosch.com/Advisory/BOSCH-SA-662084.html",
"tags": [
"Vendor Advisory"
],
"source": "psirt@bosch.com"
},
{
"url": "https://psirt.bosch.com/Advisory/BOSCH-SA-662084.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@bosch.com",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in unauthorized download of a backup. In order to exploit the vulnerability, the adversary needs to download the backup directly after a backup triggered by a legitimate user has been completed."
},
{
"lang": "es",
"value": "Se presenta una vulnerabilidad potencial de control de acceso inapropiado en el mecanismo de copia de seguridad (backup) del Smart Home Controller (SHC) de Bosch anteriores de la versión 9.8.905, que puede conllevar a la descarga no autorizada de una copia de seguridad. Para explotar la vulnerabilidad, el adversario necesita descargar la copia de seguridad directamente despúes de haber completado una copia de seguridad iniciada por un usuario legítimo."
}
],
"lastModified": "2026-06-17T02:13:49.540",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:bosch:smart_home_controller_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "208D1A1D-4982-457F-A29B-0BE857355DC5",
"versionEndExcluding": "9.8.905"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:bosch:smart_home_controller:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "83665608-FC8C-4C92-9DAD-A025433DDD33"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@bosch.com"
}