CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2019-6958

CVSS 9.1v3.1pub. 2019-05-29upd. 2024-11-21

A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Configuration Manager, Building Integration System (BIS) with Video Engine, Access Professional Edition (APE), Access Easy Controller (AEC), Bosch Video Client (BVC) and Video SDK (VSDK). The RCP+ network port allows access without authentication. Adding authentication feature to the respective library fixes the issue. The issue is classified as "CWE-284: Improper Access Control." This vulnerability, for example, allows a potential attacker to delete video or read video data.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Bosch Access Easy Controller

    HW
    Bosch
    all versions
  • Bosch Access Easy Controller Firmware

    OS
    Bosch
    2.1.8.52.1.9.02.1.9.12.1.9.3
  • Bosch Access Professional Edition

    APP
    Bosch
    3.0 – 3.7
  • Bosch Video Client

    APP
    Bosch
    < 1.7.6.079
  • Bosch Video Management System

    APP
    Bosch
    ≤ 9.0
  • Bosch Building Integration System

    APP
    Bosch
    4.54.64.6.12.2 – 4.4
  • Bosch Configuration Manager

    APP
    Bosch
    < 6.10
  • Bosch Dip 2000

    HW
    Bosch
    all versions
  • Bosch Dip 2000 Firmware

    OS
    Bosch
    < 0380.037
  • Bosch Dip 3000

    HW
    Bosch
    all versions
  • Bosch Dip 3000 Firmware

    OS
    Bosch
    all versions
  • Bosch Dip 5000

    HW
    Bosch
    all versions
  • Bosch Dip 5000 Firmware

    OS
    Bosch
    < 038.037
  • Bosch Dip 7000

    HW
    Bosch
    gen1gen2
  • Bosch Dip 7000 Firmware

    OS
    Bosch
    all versions
  • Bosch Video Sdk

    APP
    Bosch
    < 6.32.0099
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2021-23859CRITICAL9.1PL ✓same product

Bosch BVMS/VRM — nieuwierzytelniona awaria usługi i obejście autoryzacji

CVE-2019-6957CRITICAL9.8PL ✓same product

Przepełnienie buforu w produktach Bosch Video/Access — zdalne wykonanie kodu

CVE-2023-29241HIGH8.1same product

Improper Information in Cybersecurity Guidebook in Bosch Building Integration System (BIS) 5.0 may lead to wro...

CVE-2021-23843HIGH8.8same product

The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC...

CVE-2021-23862HIGH7.2same product

A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary c...