PT-2022-21357 · Bosch · Bvms+1

Published

2022-09-30

·

Updated

2022-10-04

·

CVE-2022-32540

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions BVMS versions 10.1.1 through 11.1.0 VIDEOJET Decoder VJD-7513 versions 10.23 through 10.30
Description The issue allows a man-in-the-middle attacker to compromise confidential video streams. This is applicable when the target system contains cameras with platform CPP13 or CPP14 and firmware version 8.x, and UDP encryption is used.
Recommendations For BVMS versions 10.1.1 through 11.1.0, update to a version that fixes the issue. For VIDEOJET Decoder VJD-7513 versions 10.23 through 10.30, update to a version that fixes the issue. As a temporary workaround, consider restricting the use of UDP encryption in systems with cameras that have platform CPP13 or CPP14 and firmware version 8.x until a patch is available.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2022-32540

Affected Products

Bvms
Videojet Decoder Vjd-7513