First published: Wed May 29 2019(Updated: )
A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Configuration Manager, Building Integration System (BIS) with Video Engine, Access Professional Edition (APE), Access Easy Controller (AEC), Bosch Video Client (BVC) and Video SDK (VSDK). The RCP+ network port allows access without authentication. Adding authentication feature to the respective library fixes the issue. The issue is classified as "CWE-284: Improper Access Control." This vulnerability, for example, allows a potential attacker to delete video or read video data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bosch Access Professional Edition | >=3.0<=3.7 | |
Bosch Bosch Video Client | <1.7.6.079 | |
Bosch Bosch Video Management System | <=9.0 | |
Bosch Building Integration System | >=2.2<=4.4 | |
Bosch Building Integration System | =4.5 | |
Bosch Building Integration System | =4.6 | |
Bosch Building Integration System | =4.6.1 | |
Bosch Configuration Manager | <6.10 | |
Bosch Video Sdk | <6.32.0099 | |
Bosch Dip 2000 Firmware | <0380.037 | |
Bosch Dip 2000 | ||
Bosch Dip 3000 Firmware | ||
Bosch Dip 3000 | ||
Bosch Dip 5000 Firmware | <038.037 | |
Bosch Dip 5000 | ||
Bosch Dip 7000 Firmware | ||
Bosch Dip 7000 | =gen1 | |
Bosch Dip 7000 | =gen2 | |
Bosch Access Easy Controller Firmware | =2.1.8.5 | |
Bosch Access Easy Controller Firmware | =2.1.9.0 | |
Bosch Access Easy Controller Firmware | =2.1.9.1 | |
Bosch Access Easy Controller Firmware | =2.1.9.3 | |
Bosch Access Easy Controller |
The recommended approach is to update the software to a fixed version as soon as possible. Until a fixed software version is installed, the mitigation approaches firewalling, and IP filtering can be utilized. For further informatation please check the published security advisory.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security vulnerability is CVE-2019-6958.
This vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Configuration Manager, Building Integration System (BIS) with Video Engine, Access Professional Edition (APE), Access Easy Controller (AEC), Bosch Bosch Video Client, Bosch Building Integration System, Bosch Configuration Manager, and Bosch Video SDK.
The severity rating of CVE-2019-6958 is critical with a score of 9.1.
To determine if your system is vulnerable to CVE-2019-6958, you can check the version of the affected software installed on your system and compare it with the list of affected versions provided in the security advisory.
Yes, a fix is available for CVE-2019-6958. It is recommended to update the affected software to the latest patched version provided by Bosch.