CVE-2020-6790: Uncontrolled Search Path Element in Bosch Video Streaming Gateway Installer
Calling an executable through an Uncontrolled Search Path Element in the Bosch Video Streaming Gateway installer up to and including version 6.45.10 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious exe in the same directory where the installer is started from.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-6790?
CVE-2020-6790 is a vulnerability that allows an attacker to execute arbitrary code on a victim's system by calling an executable through an Uncontrolled Search Path Element in the Bosch Video Streaming Gateway installer.
What is the severity of CVE-2020-6790?
CVE-2020-6790 is classified as a high severity vulnerability with a severity value of 7.8.
Which version of Bosch Video Streaming Gateway is affected by CVE-2020-6790?
Bosch Video Streaming Gateway up to and including version 6.45.10 is affected by CVE-2020-6790.
How can an attacker exploit CVE-2020-6790?
An attacker can exploit CVE-2020-6790 by tricking a victim into placing a malicious executable on their system, which can then be executed.
Is there a fix for CVE-2020-6790?
Yes, the fix for CVE-2020-6790 is to update the Bosch Video Streaming Gateway installer to a version that is not affected by the vulnerability.