CVE-2019-7728

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
22/02/2019
Last modified:
17/06/2026

Description

An issue was discovered in the Bosch Smart Camera App before 1.3.1 for Android. Due to improperly implemented TLS certificate checks, a malicious actor could potentially succeed in executing a man-in-the-middle attack for some connections. (The Bosch Smart Home App is not affected. iOS Apps are not affected.)

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bosch:smart_camera:*:*:*:*:*:android:*:* 1.3.1 (excluding)