First published: Fri Feb 07 2020(Updated: )
Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on the system. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.0.329 and 7.5 and older. This affects Bosch DIVAR IP 3000 and DIVAR IP 7000 if a vulnerable BVMS version is installed.
Credit: psirt@bosch.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bosch Bosch Video Management System Mobile Video Service | <=7.5 | |
Bosch Bosch Video Management System Mobile Video Service | >=8.0<=8.0.0.329 | |
Bosch Bosch Video Management System Mobile Video Service | >=9.0<=9.0.0.827 | |
Bosch Bosch Video Management System Mobile Video Service | >=10.0<=10.0.0.1225 | |
Bosch Divar Ip 3000 Firmware | ||
Bosch DIVAR IP 3000 | ||
Bosch Divar Ip 7000 Firmware | ||
Bosch Divar Ip 7000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6770 is a vulnerability that allows an unauthenticated remote attacker to execute arbitrary code on the system.
CVE-2020-6770 affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.0.329, and 7.5 and older.
Bosch DIVAR IP 3000 is affected by CVE-2020-6770.
CVE-2020-6770 has a severity rating of 9.8 (Critical).
To fix CVE-2020-6770, update to a version of Bosch BVMS or DIVAR IP 3000 that is not affected by the vulnerability.