CVE-2020-6781

MEDIUM

Bosch Smart Home System App for iOS < 9.17.1 - Improper Certificate Validation

Title source: llm
STIX 2.1

Description

Improper certificate validation for certain connections in the Bosch Smart Home System App for iOS prior to version 9.17.1 potentially allows to intercept video contents by performing a man-in-the-middle attack.

References (1)

Core 1
Core References

Scores

CVSS v3 6.8
EPSS 0.0045
EPSS Percentile 35.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

Details

CWE
CWE-295
Status published
Products (1)
bosch/smart_home < 9.17.1
Published Sep 16, 2020
Tracked Since Feb 18, 2026