Improper certificate validation for certain connections in the Bosch Smart Home System App for iOS prior to version 9.17.1 potentially allows to intercept video contents by performing a man-in-the-middle attack.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://psirt.bosch.com/security-advisories/BOSCH-SA-347336.html | vendor advisory |