CVE-2020-6767: Path Traversal in Bosch Video Management System (BVMS)
A path traversal vulnerability in the Bosch Video Management System (BVMS) FileTransferService allows an authenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5 and older. This affects Bosch BVMS Viewer versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5 and older. This affects Bosch DIVAR IP 3000, DIVAR IP 7000 and DIVAR IP all-in-one 5000 if a vulnerable BVMS version is installed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If a vulnerable Bosch BVMS version is installed (BVMS Viewer 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329, or 7.5 and older; and BVMS 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329, or 7.5 and older), restrict access so the FileTransferService is not reachable by untrusted networks/clients beyond what is required for authenticated access.
Event History
Frequently Asked Questions
What is the vulnerability ID for this path traversal vulnerability?
The vulnerability ID for this path traversal vulnerability is CVE-2020-6767.
What is the affected software for this vulnerability?
The affected software for this vulnerability is the Bosch Video Management System (BVMS) FileTransferService.
How does this vulnerability impact the affected software?
This vulnerability allows an authenticated remote attacker to read arbitrary files from the Central Server.
What are the affected versions of the Bosch BVMS?
The affected versions of the Bosch BVMS are 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329, and 7.5 and older.
What is the severity level of this vulnerability?
The severity level of this vulnerability is high.
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The Common Weakness Enumeration (CWE) ID for this vulnerability is CWE-22.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability in the following references: [Link 1](https://media.boschsecurity.com/fs/media/pb/security_advisories/bosch-sa-381489-bt_cve-2020-6767_securityadvisory_bvms_pathtraversal.pdf) and [Link 2](https://psirt.bosch.com/security-advisories/BOSCH-SA-381489-BT.html).