← Back

Bose

bose

5 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Soundtouch
soundtouch
Soundtouch 30
soundtouch_30

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bose
1Soundtouch
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in the Bose Soundtouch app 18.1.4 for iOS. There is no frontend input validation of the device name. A malicious device name can execute JavaScript on the registered Bose User Account if a speaker...Show more
An issue was discovered in the Bose Soundtouch app 18.1.4 for iOS. There is no frontend input validation of the device name. A malicious device name can execute JavaScript on the registered Bose User Account if a speaker has been connected to the app.Show less
1Bose
1Soundtouch
Nov 21, 2024
Mar 24, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Bose SoundTouch devices allows remote attackers to achieve remote control via a crafted web site that uses the WebSocket Protocol.
1Bose
1Soundtouch
Nov 21, 2024
Mar 24, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Bose SoundTouch devices allow XSS via a crafted public playlist from Spotify.
1Bose
1Soundtouch
Nov 21, 2024
Mar 24, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Bose SoundTouch devices allow XSS via crafted song data from a music service, as demonstrated by Pandora.
1Bose
1Soundtouch 30
May 13, 2026
May 1, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The Multicast DNS (mDNS) responder used in BOSE Soundtouch 30 inadvertently responds to IPv4 unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traf...Show more
The Multicast DNS (mDNS) responder used in BOSE Soundtouch 30 inadvertently responds to IPv4 unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP packets.Show less