← Voltar para CVEs
CVE-2019-6957
CRITICAL9.8
Descricao
A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Video Recording Manager (VRM), Video Streaming Gateway (VSG), Configuration Manager, Building Integration System (BIS) with Video Engine, Access Professional Edition (APE), Access Easy Controller (AEC), Bosch Video Client (BVC) and Video SDK (VSDK). The vulnerability potentially allows the unauthorized execution of code in the system via the network interface.
Detalhes CVE
Pontuacao CVSS v3.19.8
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado5/29/2019
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0
Produtos afetados
bosch:access_easy_controllerbosch:access_easy_controller_firmwarebosch:access_professional_editionbosch:bosch_video_clientbosch:bosch_video_management_systembosch:building_integration_systembosch:configuration_managerbosch:dip_2000bosch:dip_2000_firmwarebosch:dip_3000bosch:dip_3000_firmwarebosch:dip_5000bosch:dip_5000_firmwarebosch:dip_7000bosch:dip_7000_firmwarebosch:video_recording_managerbosch:video_sdkbosch:video_streaming_gateway
Fraquezas (CWE)
CWE-787
Referencias
https://media.boschsecurity.com/fs/media/pb/security_advisories/bosch-2019-0403bt-cve-2019-6957_security_advisory_software_buffer_overflow.pdf(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.