HIGH
Uncontrolled Search Path Element in Bosch Video Recording Manager Installer
Published Mar 25, 2021
7.8
HIGHCVSS 3.1
EPSS 0.35%
Description
Loading a DLL through an Uncontrolled Search Path Element in the Bosch Video Recording Manager installer up to and including version 3.82.0055 for 3.82, up to and including version 3.81.0064 for 3.81 and 3.71 and older potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious DLL in the same directory where the installer is started from.
Affected products
-
- Version 3.71 and older allStatusaffectedConstraints-
- Version 3.81StatusaffectedConstraints<=3.81.0064
- Version 3.82StatusaffectedConstraints<=3.82.0055
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Bosch | Video Recording Manager | n/a |
|
OR
- ≤ 3.71
- ≥ 3.81 · ≤ 3.81.0064
- ≥ 3.82 · ≤ 3.82.0055
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (1)
- https://psirt.bosch.com/security-advisories/bosch-sa-835563-bt.html x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://psirt.bosch.com/security-advisories/bosch-sa-835563-bt.html | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner bosch
Published Mar 25, 2021
Updated Sep 16, 2024
Reserved Jan 10, 2020
Link CVE-2020-6786
CISA Vulnrichment
Updated n/a