PT-2021-12597 · Bosch · Bosch Bvms Viewer+4
Published
2021-03-25
·
Updated
2021-03-25
·
CVE-2020-6785
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Bosch BVMS versions 10.1.0, 10.0.1, 10.0.0 and 9.0.0 and older
Bosch BVMS Viewer versions 10.1.0, 10.0.1, 10.0.0 and 9.0.0 and older
Bosch DIVAR IP 7000 R2 with BVMS versions prior to 10.1.1
Bosch DIVAR IP all-in-one 5000 with BVMS versions prior to 10.1.1
Bosch DIVAR IP all-in-one 7000 with BVMS versions prior to 10.1.1
Description:
Loading a DLL through an Uncontrolled Search Path Element in the affected software potentially allows an attacker to execute arbitrary code on a victim's system. This issue affects both the installer and the installed application.
Recommendations:
For Bosch BVMS versions 10.1.0, 10.0.1, 10.0.0 and 9.0.0 and older, update to version 10.1.1 or later.
For Bosch BVMS Viewer versions 10.1.0, 10.0.1, 10.0.0 and 9.0.0 and older, update to version 10.1.1 or later.
For Bosch DIVAR IP 7000 R2, update the BVMS version to 10.1.1 or later.
For Bosch DIVAR IP all-in-one 5000, update the BVMS version to 10.1.1 or later.
For Bosch DIVAR IP all-in-one 7000, update the BVMS version to 10.1.1 or later.
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bosch Bvms
Bosch Bvms Viewer
Bosch Divar Ip 7000 R2
Bosch Divar Ip All-In-One 5000
Bosch Divar Ip All-In-One 7000