PT-2020-19222 · Bosch · Bosch Divar Ip 3000+2

Published

2020-02-07

·

Updated

2020-02-12

·

CVE-2020-6770

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bosch BVMS versions 7.5 and older Bosch BVMS versions 8.0 through 8.0.0.329 Bosch BVMS versions 9.0 through 9.0.0.827 Bosch BVMS versions 10.0 through 10.0.0.1225 Bosch DIVAR IP 3000 (affected versions not specified) Bosch DIVAR IP 7000 (affected versions not specified)
Description The issue allows an unauthenticated remote attacker to execute arbitrary code on the system due to deserialization of untrusted data in the BVMS Mobile Video Service.
Recommendations For Bosch BVMS versions 7.5 and older, update to a version newer than 10.0.0.1225. For Bosch BVMS versions 8.0 through 8.0.0.329, update to a version newer than 10.0.0.1225. For Bosch BVMS versions 9.0 through 9.0.0.827, update to a version newer than 10.0.0.1225. For Bosch BVMS versions 10.0 through 10.0.0.1225, update to a version newer than 10.0.0.1225. For Bosch DIVAR IP 3000 and DIVAR IP 7000, ensure that a non-vulnerable BVMS version is installed.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6770

Affected Products

Bosch Bvms
Bosch Divar Ip 3000
Bosch Divar Ip 7000