PT-2020-19222 · Bosch · Bosch Divar Ip 3000+2
Published
2020-02-07
·
Updated
2020-02-12
·
CVE-2020-6770
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Bosch BVMS versions 7.5 and older
Bosch BVMS versions 8.0 through 8.0.0.329
Bosch BVMS versions 9.0 through 9.0.0.827
Bosch BVMS versions 10.0 through 10.0.0.1225
Bosch DIVAR IP 3000 (affected versions not specified)
Bosch DIVAR IP 7000 (affected versions not specified)
Description
The issue allows an unauthenticated remote attacker to execute arbitrary code on the system due to deserialization of untrusted data in the BVMS Mobile Video Service.
Recommendations
For Bosch BVMS versions 7.5 and older, update to a version newer than 10.0.0.1225.
For Bosch BVMS versions 8.0 through 8.0.0.329, update to a version newer than 10.0.0.1225.
For Bosch BVMS versions 9.0 through 9.0.0.827, update to a version newer than 10.0.0.1225.
For Bosch BVMS versions 10.0 through 10.0.0.1225, update to a version newer than 10.0.0.1225.
For Bosch DIVAR IP 3000 and DIVAR IP 7000, ensure that a non-vulnerable BVMS version is installed.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bosch Bvms
Bosch Divar Ip 3000
Bosch Divar Ip 7000