PT-2020-19220 · Bosch · Bosch Bvms Viewer+4

Published

2020-02-07

·

Updated

2020-02-12

·

CVE-2020-6768

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Bosch BVMS versions 7.5 and older Bosch BVMS versions 8.0 through 8.0.329 Bosch BVMS versions 9.0 through 9.0.0.827 Bosch BVMS versions 10.0 through 10.0.0.1225 Bosch BVMS Viewer versions 7.5 and older Bosch BVMS Viewer versions 8.0 through 8.0.329 Bosch BVMS Viewer versions 9.0 through 9.0.0.827 Bosch BVMS Viewer versions 10.0 through 10.0.0.1225 Bosch DIVAR IP 3000 (if a vulnerable BVMS version is installed) Bosch DIVAR IP 7000 (if a vulnerable BVMS version is installed) Bosch DIVAR IP all-in-one 5000 (if a vulnerable BVMS version is installed)
Description A path traversal issue allows an unauthenticated remote attacker to read arbitrary files from the Central Server.
Recommendations For Bosch BVMS versions 7.5 and older, update to a version newer than 10.0.0.1225. For Bosch BVMS versions 8.0 through 8.0.329, update to a version newer than 10.0.0.1225. For Bosch BVMS versions 9.0 through 9.0.0.827, update to a version newer than 10.0.0.1225. For Bosch BVMS versions 10.0 through 10.0.0.1225, update to a version newer than 10.0.0.1225. For Bosch BVMS Viewer versions 7.5 and older, update to a version newer than 10.0.0.1225. For Bosch BVMS Viewer versions 8.0 through 8.0.329, update to a version newer than 10.0.0.1225. For Bosch BVMS Viewer versions 9.0 through 9.0.0.827, update to a version newer than 10.0.0.1225. For Bosch BVMS Viewer versions 10.0 through 10.0.0.1225, update to a version newer than 10.0.0.1225. For Bosch DIVAR IP 3000, DIVAR IP 7000, and DIVAR IP all-in-one 5000, ensure that a non-vulnerable BVMS version is installed.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6768

Affected Products

Bosch Bvms
Bosch Bvms Viewer
Bosch Divar Ip 3000
Bosch Divar Ip 7000
Bosch Divar Ip All-In-One 5000