Back to overview

CVE-2020-6769

CRITICAL
10.0
CVSS 3.1
Description
Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote attacker to retrieve and set arbitrary configuration data of the Video Streaming Gateway. A successful attack can impact the confidentiality and availability of live and recorded video data of all cameras configured to be controlled by the VSG as well as the recording storage associated with the VSG. This affects Bosch Video Streaming Gateway versions 6.45 <= 6.45.08, 6.44 <= 6.44.022, 6.43 <= 6.43.0023 and 6.42.10 and older. This affects Bosch DIVAR IP 3000, DIVAR IP 7000 and DIVAR IP all-in-one 5000 if a vulnerable VSG version is installed with BVMS. This affects Bosch DIVAR IP 2000 <= 3.62.0019 and DIVAR IP 5000 <= 3.80.0039 if the corresponding port 8023 has been opened in the device's firewall.

Metadata

CVE ID
CVE-2020-6769
State
PUBLISHED
Assigner
bosch
Reserved
2020-01-10 00:00 UTC
Published
2020-02-07 19:57 UTC
Last updated
2024-09-16 21:03 UTC
Primary CWE
CWE-306
CWE-306 Missing Authentication for Critical Function
Vendor / Product
Bosch / DIVAR IP 2000
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (6)
VendorProductPlatformVersions
Bosch DIVAR IP 2000 unspecified ≤ 3.62.0019
Bosch DIVAR IP 3000 All
Bosch DIVAR IP 5000 unspecified ≤ 3.80.0039
Bosch DIVAR IP 7000 All
Bosch DIVAR IP all-in-one 5000 All
Bosch Video Streaming Gateway 6.45 ≤ 6.45.08, 6.44 ≤ 6.44.0030, 6.43 ≤ 6.43.0023, 6.42 and older ≤ 6.42.10
Weakness (CWE)
CWESourceDescription
CWE-306 cna CWE-306 Missing Authentication for Critical Function
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview