Vulnerability index

Browse CVEs

102 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

B426 Firmware MEDIUM 5.9
CVE-2021-23846

When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a…

Mitigation only
Fix from $1,600 2021-06-18
Cpp4 Firmware CRITICAL 9.8
CVE-2021-23853

In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP headers through crafted URLs.

Mitigation only
Fix from $2,300 2021-06-09
Cpp6 Firmware CRITICAL 9.1
CVE-2021-23847

A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or chang…

Fix: 7.80.0129+
Fix from $2,300 2021-06-09
Cpp4 Firmware MEDIUM 6.1
CVE-2021-23848

An error in the URL handler Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledg…

Mitigation only
Fix from $1,600 2021-06-09
Cpp6 Firmware MEDIUM 6.1
CVE-2021-23854

An error in the handling of a page parameter in Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. This …

Mitigation only
Fix from $1,600 2021-06-09
Ip Helper HIGH 7.8
CVE-2020-6771

Loading a DLL through an Uncontrolled Search Path Element in Bosch IP Helper up to and including version 1.00.0008 potentially allows an attacker to …

Fix: after 1.00.0008
Fix from $1,950 2021-03-25
Video Management System HIGH 7.8
CVE-2020-6785

Loading a DLL through an Uncontrolled Search Path Element in Bosch BVMS and BVMS Viewer in versions 10.1.0, 10.0.1, 10.0.0 and 9.0.0 and older potent…

Fix: 9.0 / 10.0.2+
Fix from $1,950 2021-03-25
Video Recording Manager HIGH 7.8
CVE-2020-6786

Loading a DLL through an Uncontrolled Search Path Element in the Bosch Video Recording Manager installer up to and including version 3.82.0055 for 3.…

Fix: after 3.82.0055
Fix from $1,950 2021-03-25
Video Client HIGH 7.8
CVE-2020-6787

Loading a DLL through an Uncontrolled Search Path Element in the Bosch Video Client installer up to and including version 1.7.6.079 potentially allow…

Fix: after 1.7.6.079
Fix from $1,950 2021-03-25
Configuration Manager HIGH 7.8
CVE-2020-6788

Loading a DLL through an Uncontrolled Search Path Element in the Bosch Configuration Manager installer up to and including version 7.21.0078 potentia…

Fix: after 7.21.0078
Fix from $1,950 2021-03-25
Monitor Wall HIGH 7.8
CVE-2020-6789

Loading a DLL through an Uncontrolled Search Path Element in the Bosch Monitor Wall installer up to and including version 10.00.0164 potentially allo…

Fix: after 10.00.0164
Fix from $1,950 2021-03-25
Video Streaming Gateway HIGH 7.8
CVE-2020-6790

Calling an executable through an Uncontrolled Search Path Element in the Bosch Video Streaming Gateway installer up to and including version 6.45.10 …

Fix: after 6.45.10
Fix from $1,950 2021-03-25
Video Recording Manager CRITICAL 9.8
CVE-2019-11684

Improper Access Control in the RCP+ server of the Bosch Video Recording Manager (VRM) component allows arbitrary and unauthenticated access to a limi…

Fix: 3.71.0034 / 3.80.0039+
Fix from $2,300 2021-02-26
Fsm 2500 Firmware CRITICAL 10.0
CVE-2020-6779

Use of Hard-coded Credentials in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows an unauthenti…

Fix: after 5.2
Fix from $2,300 2021-01-26
Praesideo Firmware HIGH 8.8
CVE-2020-6776

A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAESENSA until and including ver…

Fix: after 4.41
Fix from $1,950 2021-01-14
Smart Home HIGH 7.4
CVE-2020-6781

Improper certificate validation for certain connections in the Bosch Smart Home System App for iOS prior to version 9.17.1 potentially allows to inte…

Fix: 9.17.1+
Fix from $1,950 2020-09-16
Recording Station Firmware HIGH 8.8
CVE-2020-6774

Improper Access Control in the Kiosk Mode functionality of Bosch Recording Station allows a local unauthenticated attacker to escape from the Kiosk M…

Mitigation only
Fix from $1,950 2020-05-27
Bosch Video Management System Mobile Video Service CRITICAL 9.8
CVE-2020-6770

Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on …

Fix: after 10.0.0.1225
Fix from $2,300 2020-02-07
Video Management System Viewer HIGH 7.5
CVE-2020-6768

A path traversal vulnerability in the Bosch Video Management System (BVMS) NoTouch deployment allows an unauthenticated remote attacker to read arbit…

Fix: after 10.0.0.1225
Fix from $1,950 2020-02-07
Video Streaming Gateway CRITICAL 9.1
CVE-2020-6769

Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote attacker to retrieve and set…

Fix: after 6.45.08
Fix from $2,300 2020-02-07
Video Management System Viewer MEDIUM 6.5
CVE-2020-6767

A path traversal vulnerability in the Bosch Video Management System (BVMS) FileTransferService allows an authenticated remote attacker to read arbitr…

Fix: after 10.0.0.1225
Fix from $1,600 2020-02-06
Access CRITICAL 9.9
CVE-2019-11898

Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The service tool is discontinued with…

Fix: 3.8+
Fix from $2,300 2019-09-12
Access HIGH 7.5
CVE-2019-11899

An unauthenticated attacker can achieve unauthorized access to sensitive data by exploiting Windows SMB protocol on a client installation. With Bosch…

Fix: after 3.7
Fix from $1,950 2019-09-12
Iot Gateway Software HIGH 7.5
CVE-2019-11601

A directory traversal vulnerability in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Softwar…

Fix: 8.2.6 / 9.2.0+
Fix from $1,950 2019-08-21
Iot Gateway Software HIGH 7.5
CVE-2019-11603

A HTTP Traversal Attack in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.0.2 allows remote attackers to read files out…

Fix: 8.2.6 / 9.0.2+
Fix from $1,950 2019-08-21
Iot Gateway Software MEDIUM 5.3
CVE-2019-11602

Leakage of stack traces in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allo…

Fix: 8.2.6 / 9.2.0+
Fix from $1,600 2019-08-21
Iot Gateway Software HIGH 8.6
CVE-2019-11897

A Server-Side Request Forgery (SSRF) vulnerability in the backup & restore functionality in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT…

Fix: 8.2.6 / 9.3.0+
Fix from $1,950 2019-08-21
Smart Home Controller Firmware HIGH 7.1
CVE-2019-11896

A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.…

Fix: 9.8.907+
Fix from $1,950 2019-05-29
Smart Home Controller Firmware MEDIUM 5.7
CVE-2019-11894

A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may res…

Fix: 9.8.905+
Fix from $1,600 2019-05-29
Smart Home Controller Firmware MEDIUM 5.3
CVE-2019-11895

A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may r…

Fix: 9.8.905+
Fix from $1,600 2019-05-29