Vulnerability index

Browse CVEs

102 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cpp13 Firmware HIGH 7.2
CVE-2023-39509

A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administrative rights to run arbitrary commands o…

Fix: after 8.90
Fix from $1,950 2023-12-18
Building Integration System Video Engine MEDIUM 5.9
CVE-2023-35867

An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a …

Fix: after 12.0
Fix from $1,600 2023-12-18
Monitor Wall HIGH 7.5
CVE-2023-32230

An improper handling of a malformed API request to an API server in Bosch BT software products can allow an unauthenticated attacker to cause a Denia…

Fix: after 10.40.0055
Fix from $1,950 2023-12-18
Cpp14 Firmware MEDIUM 5.3
CVE-2022-41677

An information disclosure vulnerability was discovered in Bosch IP camera devices allowing an unauthenticated attacker to retrieve information (like …

Fix: after 8.80
Fix from $1,600 2023-12-18
Rts Vlink Virtual Matrix HIGH 7.2
CVE-2023-34999

A command injection vulnerability exists in RTS VLink Virtual Matrix Software Versions v5 (< 5.7.6) and v6 (< 6.5.0) that allows an attacker to perfo…

Fix: 5.7.6 / 6.5.0+
Fix from $1,950 2023-09-18
Building Integration System HIGH 7.1
CVE-2023-29241

Improper Information in Cybersecurity Guidebook in Bosch Building Integration System (BIS) 5.0 may lead to wrong configuration which allows local use…

Mitigation only
Fix from $1,950 2023-06-30
Video Management System HIGH 7.7
CVE-2023-28175

Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access resources within the trusted …

Fix: after 11.1.1
Fix from $1,950 2023-06-15
Cpp13 Firmware MEDIUM 6.5
CVE-2023-32229

Due to an error in the software interface to the secure element chip on Bosch IP cameras of family CPP13 and CPP14, the chip can be permanently damag…

Fix: 8.48.0017 / 8.80.0090+
Fix from $1,600 2023-06-15
B420 Firmware HIGH 8.8
CVE-2022-47648

An Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring any sort of authorization or au…

Mitigation only
Fix from $1,950 2023-02-08
Bosch Video Management System MEDIUM 5.9
CVE-2022-32540

Information Disclosure in Operator Client application in BVMS 10.1.1, 11.0 and 11.1.0 and VIDEOJET Decoder VJD-7513 versions 10.23 and 10.30 allows m…

Fix: after 11.1.0
Fix from $1,600 2022-09-30
Bf Os HIGH 7.5
CVE-2022-36301

BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device password.

Fix: after 3.83
Fix from $1,950 2022-08-01
Bf Os MEDIUM 5.4
CVE-2022-36302

File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access different re…

Fix: after 3.83
Fix from $1,600 2022-08-01
Pra Es8p2s Firmware CRITICAL 9.8
CVE-2022-32534

The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command injection through its diagnostic…

Fix: after 1.01.05
Fix from $2,300 2022-06-23
Pra Es8p2s Firmware CRITICAL 9.8
CVE-2022-32535

The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 runs its web server with root privilege. In combination with CVE-2022-23534 this c…

Fix: after 1.01.05
Fix from $2,300 2022-06-23
Pra Es8p2s Firmware HIGH 8.8
CVE-2022-32536

The user access rights validation in the web server of the Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 was insufficient. This woul…

Fix: after 1.01.05
Fix from $1,950 2022-06-23
Autodome Ip 4000i Firmware HIGH 7.2
CVE-2021-23850

A specially crafted TCP/IP packet may cause a camera recovery image telnet interface to crash. It may also cause a buffer overflow which could enable…

Mitigation only
Fix from $1,950 2022-03-30
Autodome Ip 4000i Firmware HIGH 7.2
CVE-2021-23851

A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer overflow which could enable …

Mitigation only
Fix from $1,950 2022-03-30
Video Security MEDIUM 6.1
CVE-2021-23863

HTML code injection vulnerability in Android Application, Bosch Video Security, version 3.2.3. or earlier, when successfully exploited allows an atta…

Fix: 3.2.4+
Fix from $1,600 2022-01-28
Amc2 Firmware HIGH 7.8
CVE-2021-23843

The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a pa…

Fix: 4.9.1+
Fix from $1,950 2022-01-19
Amc2 Firmware HIGH 7.1
CVE-2021-23842

Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An attacker could retrieve the ke…

Fix: 4.9.1+
Fix from $1,950 2022-01-19
Bosch Video Management System HIGH 7.5
CVE-2021-23859

An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM inst…

Fix: 10.0.2+
Fix from $1,950 2021-12-08
Bosch Video Management System HIGH 7.2
CVE-2021-23862

A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in system context. This issue a…

Fix: 10.0.2+
Fix from $1,950 2021-12-08
Bosch Video Management System MEDIUM 6.5
CVE-2021-23861

By executing a special command, an user with administrative rights can get access to extended debug functionality on the VRM allowing an impact on in…

Fix: 10.0.2+
Fix from $1,600 2021-12-08
Bosch Video Management System MEDIUM 6.1
CVE-2021-23860

An error in a page handler of the VRM may lead to a reflected cross site scripting (XSS) in the web-based interface. To exploit this vulnerability an…

Fix: 10.0.2+
Fix from $1,600 2021-12-08
Rexroth Indramotion Mlc L20 Firmware CRITICAL 9.8
CVE-2021-23857

Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combin…

Fix: after 12
Fix from $2,300 2021-10-04
Rexroth Indramotion Xlc Firmware HIGH 7.5
CVE-2021-23855

The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashing algorithm and therefore al…

Mitigation only
Fix from $1,950 2021-10-04
Rexroth Indramotion Mlc L20 Firmware HIGH 7.5
CVE-2021-23858

Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can …

Fix: after 12
Fix from $1,950 2021-10-04
Rexroth Indramotion Mlc L20 Firmware MEDIUM 6.1
CVE-2021-23856

The web server is vulnerable to reflected XSS and therefore an attacker might be able to execute scripts on a client’s computer by sending the client…

Mitigation only
Fix from $1,600 2021-10-04
Cpp4 Firmware HIGH 8.8
CVE-2021-23849

A vulnerability in the web-based interface allows an unauthenticated remote attacker to trigger actions on an affected system on behalf of another us…

Mitigation only
Fix from $1,950 2021-08-05
B426 Firmware HIGH 8.8
CVE-2021-23845

This vulnerability could allow an attacker to hijack a session while a user is logged in the configuration web page. This vulnerability was discovere…

Fix: 03.08 / 03.10+
Fix from $1,950 2021-06-18