{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-30T00:45:44.967","vulnerabilities":[{"cve":{"id":"CVE-2019-11895","sourceIdentifier":"psirt@bosch.com","published":"2019-05-29T21:29:02.120","lastModified":"2026-06-17T02:13:49.660","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a successful denial of service of the SHC and connected sensors and actuators. In order to exploit the vulnerability, the adversary needs to have successfully paired an app or service, which requires user interaction."},{"lang":"es","value":"Se presenta una vulnerabilidad potencial de control de acceso inapropiado en la interfaz JSON-RPC del Smart Home Controller (SHC) de Bosch anteriores de la versión 9.8.905, que puede conllevar a una Denegación de Servicio con éxito a del SHC y los sensores y transmisores de fuerza conectados. Para aprovechar la vulnerabilidad, el adversario necesita haber emparejado con exito una aplicación o servicio, que requiere interacción con el usuario."}],"affected":[{"source":"psirt@bosch.com","affectedData":[{"vendor":"Bosch","product":"Smart Home Controller","versions":[{"version":"unspecified","lessThan":"9.8.905","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":3.6}],"cvssMetricV30":[{"source":"psirt@bosch.com","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:N/A:C","baseScore":7.1,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"psirt@bosch.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:bosch:smart_home_controller_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"9.8.905","matchCriteriaId":"208D1A1D-4982-457F-A29B-0BE857355DC5"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:bosch:smart_home_controller:*:*:*:*:*:*:*:*","matchCriteriaId":"0CB28E5D-21D5-4DEE-8D84-FA1F4664362F"}]}]}],"references":[{"url":"https://psirt.bosch.com/Advisory/BOSCH-SA-662084.html","source":"psirt@bosch.com","tags":["Vendor Advisory"]},{"url":"https://psirt.bosch.com/Advisory/BOSCH-SA-662084.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}