CVE-2026-10764: Information disclosure in BVMS 4.5 up to 12.3
Published Sep 30, 2026
·Updated
Information disclosure in BVMS 4.5 up to 12.3 including allows man-in-the-middle attackers to gain unauthorized access to sensitive data.
Affected Software
1 affected component
Bosch BVMS>=4.5<=12.3
Event History
Sep 30, 2026
CVE Published
via MITRE·09:43 AM
Data Sourced
via MITRE·09:43 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What must an attacker be able to do to exploit this issue?
The attacker must be able to perform a man-in-the-middle attack on network communications. The CVSS vector indicates no privileges or user interaction are required, but exploitation has high attack complexity.
2
Is service availability affected by this vulnerability?
No availability impact is indicated. The reported impact is high for confidentiality and integrity, with scope marked as changed.