Improper Access Control for Bosch Video Systems, PSIM and Access Control Systems
Published May 29, 2019
9.1
CRITICALCVSS 3.1
EPSS 1.52%
Description
A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Configuration Manager, Building Integration System (BIS) with Video Engine, Access Professional Edition (APE), Access Easy Controller (AEC), Bosch Video Client (BVC) and Video SDK (VSDK). The RCP+ network port allows access without authentication. Adding authentication feature to the respective library fixes the issue. The issue is classified as "CWE-284: Improper Access Control." This vulnerability, for example, allows a potential attacker to delete video or read video data.
Affected products
No data.
Configuration 1
- ≥ 3.0 · ≤ 3.7
- < 1.7.6.079
- ≤ 9.0
- ≥ 2.2 · ≤ 4.4
- 4.5
- 4.6
- 4.6.1
- < 6.10
- < 6.32.0099
Configuration 2
- < 0380.037
Configuration 3
- n/a
Configuration 4
- < 038.037
Configuration 5
Configuration 6
- 2.1.8.5
- 2.1.9.0
- 2.1.9.1
- 2.1.9.3
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
The recommended approach is to update the software to a fixed version as soon as possible. Until a fixed software version is installed, the mitigation approaches firewalling, and IP filtering can be utilized.
For further informatation please check the published security advisory.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.52% (0.01515) | 73.58th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.52% (0.01515) | 71.12th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.17% (0.00168) | 54.13th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.17% (0.00168) | 53.14th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.13% (0.00131) | 46.20th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.89% (0.00885) | 24.24th | v2 (v2022.01.01) |
| Feb 4, 2022 | 9.03% (0.09029) | 86.86th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.84% (0.01840) | 47.83th | v5 (v2026.06.15) |
| Jan 6, 2022 | 1.84% (0.01840) | 47.32th | v1 |
| Sep 1, 2021 | 0.42% (0.00416) | 25.53th | v1 |
| Apr 14, 2021 | 0.42% (0.00416) | 0.00th | v1 |
References (1)
- https://media.boschsecurity.com/fs/media/pb/security_advisories/bosch-2019-0404bt-cve-2019-6958_security_advisory_improper_access_control.pdf x_refsource_CONFIRMMitigationVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://media.boschsecurity.com/fs/media/pb/security_advisories/bosch-2019-0404bt-cve-2019-6958_security_advisory_improper_access_control.pdf | x_refsource_CONFIRMMitigationVendor Advisory |
Change history (0)
No recorded changes yet.