Unrated severityNVD Advisory· Published Aug 21, 2019· Updated Sep 17, 2024
Server-side request forgery in the backup & restore functionality of ProSyst mBS SDK and Bosch IoT Gateway Software
CVE-2019-11897
Description
A Server-Side Request Forgery (SSRF) vulnerability in the backup & restore functionality in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.3.0 allows a remote attacker to forge GET requests to arbitrary URLs. In addition, this could potentially allow an attacker to read sensitive zip files from the local server.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- psirt.bosch.com/Advisory/BOSCH-SA-562575.htmlmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.