CVE-2020-6770: Deserialization of Untrusted Data in Bosch BVMS Mobile Video Service
Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on the system. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.0.329 and 7.5 and older. This affects Bosch DIVAR IP 3000 and DIVAR IP 7000 if a vulnerable BVMS version is installed.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-6770?
CVE-2020-6770 is a vulnerability that allows an unauthenticated remote attacker to execute arbitrary code on the system.
Which software versions are affected by CVE-2020-6770?
CVE-2020-6770 affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.0.329, and 7.5 and older.
Is Bosch DIVAR IP 3000 affected by CVE-2020-6770?
Bosch DIVAR IP 3000 is affected by CVE-2020-6770.
What is the severity of CVE-2020-6770?
CVE-2020-6770 has a severity rating of 9.8 (Critical).
How can I fix CVE-2020-6770?
To fix CVE-2020-6770, update to a version of Bosch BVMS or DIVAR IP 3000 that is not affected by the vulnerability.