PT-2022-21357 · Bosch · Bvms+1
Published
2022-09-30
·
Updated
2022-10-04
·
CVE-2022-32540
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
BVMS versions 10.1.1 through 11.1.0
VIDEOJET Decoder VJD-7513 versions 10.23 through 10.30
Description
The issue allows a man-in-the-middle attacker to compromise confidential video streams. This is applicable when the target system contains cameras with platform CPP13 or CPP14 and firmware version 8.x, and UDP encryption is used.
Recommendations
For BVMS versions 10.1.1 through 11.1.0, update to a version that fixes the issue.
For VIDEOJET Decoder VJD-7513 versions 10.23 through 10.30, update to a version that fixes the issue.
As a temporary workaround, consider restricting the use of UDP encryption in systems with cameras that have platform CPP13 or CPP14 and firmware version 8.x until a patch is available.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bvms
Videojet Decoder Vjd-7513