CVE-2019-6958 Information
Feb 14, 2021
cve
Description
A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below DIVAR IP 2000 3000 5000 and 7000 Configuration Manager Building Integration System (BIS) with Video Engine Access Professional Edition (APE) Access Easy Controller (AEC) Bosch Video Client (BVC) and Video SDK (VSDK). The RCP+ network port allows access without authentication. Adding authentication feature to the respective library fixes the issue. The issue is classified as \CWE-284: Improper Access Control.\ This vulnerability for example allows a potential attacker to delete video or read video data.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Reference
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
HIGH
Base Severity
9.1
Share on: