CVE-2020-6770
07.02.2020, 21:15
Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on the system. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.0.329 and 7.5 and older. This affects Bosch DIVAR IP 3000 and DIVAR IP 7000 if a vulnerable BVMS version is installed.Enginsight
Vendor | Product | Version |
---|---|---|
bosch | bosch_video_management_system_mobile_video_service | 𝑥 ≤ 7.5 |
bosch | bosch_video_management_system_mobile_video_service | 8.0 ≤ 𝑥 ≤ 8.0.0.329 |
bosch | bosch_video_management_system_mobile_video_service | 9.0 ≤ 𝑥 ≤ 9.0.0.827 |
bosch | bosch_video_management_system_mobile_video_service | 10.0 ≤ 𝑥 ≤ 10.0.0.1225 |
bosch | divar_ip_3000_firmware | - |
bosch | divar_ip_7000_firmware | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration