CyberSec.Space Logo
Back to CVE Browser

CVE-2019-6958

CRITICAL
9.1
CVSS Severity Score
EPSS Score0.0020%
EPSS Percentile3.98th
PublishedMay 29, 2019
Last ModifiedNov 21, 2024

Vulnerability Description

A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Configuration Manager, Building Integration System (BIS) with Video Engine, Access Professional Edition (APE), Access Easy Controller (AEC), Bosch Video Client (BVC) and Video SDK (VSDK). The RCP+ network port allows access without authentication. Adding authentication feature to the respective library fixes the issue. The issue is classified as "CWE-284: Improper Access Control." This vulnerability, for example, allows a potential attacker to delete video or read video data.

Affected Platforms (CPE)

πŸ“¦
Bosch

Access Professional Edition

>= 3.0 and <= 3.7
πŸ“¦
Bosch

Bosch Video Client

< 1.7.6.079
πŸ“¦
Bosch

Bosch Video Management System

<= 9.0
πŸ“¦
Bosch

Building Integration System

>= 2.2 and <= 4.4
πŸ“¦
Bosch

Building Integration System

= 4.5
πŸ“¦
Bosch

Building Integration System

= 4.6
πŸ“¦
Bosch

Building Integration System

= 4.6.1
πŸ“¦
Bosch

Configuration Manager

< 6.10
πŸ“¦
Bosch

Video Sdk

< 6.32.0099
πŸ’»
Bosch

Dip 2000 Firmware

< 0380.037
πŸ’»
Bosch

Dip 3000 Firmware

All versions
πŸ’»
Bosch

Dip 5000 Firmware

< 038.037
πŸ’»
Bosch

Dip 7000 Firmware

All versions
πŸ’»
Bosch

Access Easy Controller Firmware

= 2.1.8.5
πŸ’»
Bosch

Access Easy Controller Firmware

= 2.1.9.0
πŸ’»
Bosch

Access Easy Controller Firmware

= 2.1.9.1
πŸ’»
Bosch

Access Easy Controller Firmware

= 2.1.9.3

References & Advisories

Related Vulnerabilities