First published: Wed Mar 24 2021(Updated: )
Calling an executable through an Uncontrolled Search Path Element in the Bosch Video Streaming Gateway installer up to and including version 6.45.10 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious exe in the same directory where the installer is started from.
Credit: psirt@bosch.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bosch Video Streaming Gateway | <=6.45.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6790 is a vulnerability that allows an attacker to execute arbitrary code on a victim's system by calling an executable through an Uncontrolled Search Path Element in the Bosch Video Streaming Gateway installer.
CVE-2020-6790 is classified as a high severity vulnerability with a severity value of 7.8.
Bosch Video Streaming Gateway up to and including version 6.45.10 is affected by CVE-2020-6790.
An attacker can exploit CVE-2020-6790 by tricking a victim into placing a malicious executable on their system, which can then be executed.
Yes, the fix for CVE-2020-6790 is to update the Bosch Video Streaming Gateway installer to a version that is not affected by the vulnerability.