Vulnerability index

Browse CVEs

102 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2023-39509 A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administrative rights to run arbitrary commands o… Cpp13 Firmware after 8.90 Fix from $1,9502023-12-18 MEDIUM 5.9 CVE-2023-35867 An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a … Building Integration System Video Engine after 12.0 Fix from $1,6002023-12-18 HIGH 7.5 CVE-2023-32230 An improper handling of a malformed API request to an API server in Bosch BT software products can allow an unauthenticated attacker to cause a Denia… Monitor Wall after 10.40.0055 Fix from $1,9502023-12-18 MEDIUM 5.3 CVE-2022-41677 An information disclosure vulnerability was discovered in Bosch IP camera devices allowing an unauthenticated attacker to retrieve information (like … Cpp14 Firmware after 8.80 Fix from $1,6002023-12-18 HIGH 7.2 CVE-2023-34999 A command injection vulnerability exists in RTS VLink Virtual Matrix Software Versions v5 (< 5.7.6) and v6 (< 6.5.0) that allows an attacker to perfo… Rts Vlink Virtual Matrix 5.7.6 / 6.5.0+ Fix from $1,9502023-09-18 HIGH 7.1 CVE-2023-29241 Improper Information in Cybersecurity Guidebook in Bosch Building Integration System (BIS) 5.0 may lead to wrong configuration which allows local use… Building Integration System Mitigation only Fix from $1,9502023-06-30 HIGH 7.7 CVE-2023-28175 Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access resources within the trusted … Video Management System after 11.1.1 Fix from $1,9502023-06-15 MEDIUM 6.5 CVE-2023-32229 Due to an error in the software interface to the secure element chip on Bosch IP cameras of family CPP13 and CPP14, the chip can be permanently damag… Cpp13 Firmware 8.48.0017 / 8.80.0090+ Fix from $1,6002023-06-15 HIGH 8.8 CVE-2022-47648 An Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring any sort of authorization or au… B420 Firmware Mitigation only Fix from $1,9502023-02-08 MEDIUM 5.9 CVE-2022-32540 Information Disclosure in Operator Client application in BVMS 10.1.1, 11.0 and 11.1.0 and VIDEOJET Decoder VJD-7513 versions 10.23 and 10.30 allows m… Bosch Video Management System after 11.1.0 Fix from $1,6002022-09-30 HIGH 7.5 CVE-2022-36301 BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device password. Bf Os after 3.83 Fix from $1,9502022-08-01 MEDIUM 5.4 CVE-2022-36302 File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access different re… Bf Os after 3.83 Fix from $1,6002022-08-01 CRITICAL 9.8 CVE-2022-32534 The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command injection through its diagnostic… Pra Es8p2s Firmware after 1.01.05 Fix from $2,3002022-06-23 CRITICAL 9.8 CVE-2022-32535 The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 runs its web server with root privilege. In combination with CVE-2022-23534 this c… Pra Es8p2s Firmware after 1.01.05 Fix from $2,3002022-06-23 HIGH 8.8 CVE-2022-32536 The user access rights validation in the web server of the Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 was insufficient. This woul… Pra Es8p2s Firmware after 1.01.05 Fix from $1,9502022-06-23 HIGH 7.2 CVE-2021-23850 A specially crafted TCP/IP packet may cause a camera recovery image telnet interface to crash. It may also cause a buffer overflow which could enable… Autodome Ip 4000i Firmware Mitigation only Fix from $1,9502022-03-30 HIGH 7.2 CVE-2021-23851 A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer overflow which could enable … Autodome Ip 4000i Firmware Mitigation only Fix from $1,9502022-03-30 MEDIUM 6.1 CVE-2021-23863 HTML code injection vulnerability in Android Application, Bosch Video Security, version 3.2.3. or earlier, when successfully exploited allows an atta… Video Security 3.2.4+ Fix from $1,6002022-01-28 HIGH 7.8 CVE-2021-23843 The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a pa… Amc2 Firmware 4.9.1+ Fix from $1,9502022-01-19 HIGH 7.1 CVE-2021-23842 Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An attacker could retrieve the ke… Amc2 Firmware 4.9.1+ Fix from $1,9502022-01-19 HIGH 7.5 CVE-2021-23859 An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM inst… Bosch Video Management System 10.0.2+ Fix from $1,9502021-12-08 HIGH 7.2 CVE-2021-23862 A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in system context. This issue a… Bosch Video Management System 10.0.2+ Fix from $1,9502021-12-08 MEDIUM 6.5 CVE-2021-23861 By executing a special command, an user with administrative rights can get access to extended debug functionality on the VRM allowing an impact on in… Bosch Video Management System 10.0.2+ Fix from $1,6002021-12-08 MEDIUM 6.1 CVE-2021-23860 An error in a page handler of the VRM may lead to a reflected cross site scripting (XSS) in the web-based interface. To exploit this vulnerability an… Bosch Video Management System 10.0.2+ Fix from $1,6002021-12-08 CRITICAL 9.8 CVE-2021-23857 Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combin… Rexroth Indramotion Mlc L20 Firmware after 12 Fix from $2,3002021-10-04 HIGH 7.5 CVE-2021-23855 The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashing algorithm and therefore al… Rexroth Indramotion Xlc Firmware Mitigation only Fix from $1,9502021-10-04 HIGH 7.5 CVE-2021-23858 Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can … Rexroth Indramotion Mlc L20 Firmware after 12 Fix from $1,9502021-10-04 MEDIUM 6.1 CVE-2021-23856 The web server is vulnerable to reflected XSS and therefore an attacker might be able to execute scripts on a client’s computer by sending the client… Rexroth Indramotion Mlc L20 Firmware Mitigation only Fix from $1,6002021-10-04 HIGH 8.8 CVE-2021-23849 A vulnerability in the web-based interface allows an unauthenticated remote attacker to trigger actions on an affected system on behalf of another us… Cpp4 Firmware Mitigation only Fix from $1,9502021-08-05 HIGH 8.8 CVE-2021-23845 This vulnerability could allow an attacker to hijack a session while a user is logged in the configuration web page. This vulnerability was discovere… B426 Firmware 03.08 / 03.10+ Fix from $1,9502021-06-18