Path Traversal in Bosch Video Management System (BVMS)
Published Feb 6, 2020
7.7
HIGHCVSS 3.1
EPSS 1.31%
Description
A path traversal vulnerability in the Bosch Video Management System (BVMS) FileTransferService allows an authenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5 and older. This affects Bosch BVMS Viewer versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5 and older. This affects Bosch DIVAR IP 3000, DIVAR IP 7000 and DIVAR IP all-in-one 5000 if a vulnerable BVMS version is installed.
Affected products
-
- Version 10.0 through 10.0.0.1225StatusaffectedConstraints-
- Version 7.0 and olderStatusaffectedConstraints-
- Version 7.5 and olderStatusaffectedConstraints-
- Version 8.0 through 8.0.0.329StatusaffectedConstraints-
- Version 9.0 through 9.0.0.827StatusaffectedConstraints-
- Version
-
- Version 10.0 through 10.0.0.1225StatusaffectedConstraints-
- Version 7.0 and olderStatusaffectedConstraints-
- Version 7.5 and olderStatusaffectedConstraints-
- Version 8.0 through 8.0.0.329StatusaffectedConstraints-
- Version 9.0 through 9.0.0.827StatusaffectedConstraints-
- Version
-
- Version AllStatusaffectedConstraints-
- Version
-
- Version AllStatusaffectedConstraints-
- Version
-
- Version AllStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Bosch | BVMS Viewer | n/a |
| ||||||||||||||||||
| Bosch | Bosch Video Management System | n/a |
| ||||||||||||||||||
| Bosch | Divar IP 3000 | n/a |
| ||||||||||||||||||
| Bosch | Divar IP 7000 | n/a |
| ||||||||||||||||||
| Bosch | DIVAR IP all-in-one 5000 | n/a |
|
Configuration 1
- ≤ 7.5
- ≥ 8.0 · ≤ 8.0.329
- ≥ 9.0 · ≤ 9.0.0.827
- ≥ 10.0 · ≤ 10.0.0.1225
Configuration 2
- ≤ 7.5
- ≥ 8.0 · ≤ 8.0.0.329
- ≥ 9.0 · ≤ 9.0.0.827
- ≥ 10.0 · ≤ 10.0.0.1225
Running on/with
- n/a
Configuration 3
- ≤ 7.5
- ≥ 8.0 · ≤ 8.0.0.329
- ≥ 9.0 · ≤ 9.0.0.827
- ≥ 10.0 · ≤ 10.0.0.1225
Running on/with
- n/a
Configuration 4
- ≤ 7.5
- ≥ 8.0 · ≤ 8.0.0.329
- ≥ 9.0 · ≤ 9.0.0.827
- ≥ 10.0 · ≤ 10.0.0.1225
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-27914 Advisory
- https://media.boschsecurity.com/fs/media/pb/security_advisories/bosch-sa-381489-bt_cve-2020-6767_securityadvisory_bvms_pathtraversal.pdf PatchVendor Advisory
- https://psirt.bosch.com/security-advisories/BOSCH-SA-381489-BT.html x_refsource_CONFIRMBroken LinkVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-27914 | Advisory | |
| https://media.boschsecurity.com/fs/media/pb/security_advisories/bosch-sa-381489-bt_cve-2020-6767_securityadvisory_bvms_pathtraversal.pdf | PatchVendor Advisory | |
| https://psirt.bosch.com/security-advisories/BOSCH-SA-381489-BT.html | x_refsource_CONFIRMBroken LinkVendor Advisory |
Change history (0)
No recorded changes yet.