Description
A path traversal vulnerability in the Bosch Video Management System (BVMS) NoTouch deployment allows an unauthenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5 and older. This affects Bosch BVMS Viewer versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5 and older. This affects Bosch DIVAR IP 3000, DIVAR IP 7000 and DIVAR IP all-in-one 5000 if a vulnerable BVMS version is installed.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None
Affected products
- Bosch / Bosch Video Management Systemunspecified – 8.0.0.329
- Bosch / Bosch Video Management Systemunspecified – 10.0.0.1225
- Bosch / Bosch Video Management Systemunspecified – 9.0.0.827
- Bosch / Bosch Video Management Systemunspecified – 7.5
- Bosch / BVMS Viewerunspecified – 10.0.0.1225
- Bosch / BVMS Viewerunspecified – 7.5
- Bosch / BVMS Viewerunspecified – 8.0.0.329
- Bosch / BVMS Viewerunspecified – 9.0.0.827
- Bosch / DIVAR IP 3000All – All
- Bosch / DIVAR IP 7000All – All
- Bosch / DIVAR IP all-in-one 5000All – All