CVE-2020-6768 Information
Feb 14, 2021
cve
Description
A path traversal vulnerability in the Bosch Video Management System (BVMS) NoTouch deployment allows an unauthenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 = 10.0.0.1225 9.0 = 9.0.0.827 8.0 = 8.0.329 and 7.5 and older. This affects Bosch BVMS Viewer versions 10.0 = 10.0.0.1225 9.0 = 9.0.0.827 8.0 = 8.0.329 and 7.5 and older. This affects Bosch DIVAR IP 3000 DIVAR IP 7000 and DIVAR IP all-in-one 5000 if a vulnerable BVMS version is installed.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
https://psirt.bosch.com/security-advisories/bosch-sa-815013-bt.html
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
7.5
Share on: