Back to overview

CVE-2020-6770

CRITICAL
10.0
CVSS 3.1
Description
Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on the system. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.0.329 and 7.5 and older. This affects Bosch DIVAR IP 3000 and DIVAR IP 7000 if a vulnerable BVMS version is installed.

Metadata

CVE ID
CVE-2020-6770
State
PUBLISHED
Assigner
bosch
Reserved
2020-01-10 00:00 UTC
Published
2020-02-07 20:08 UTC
Last updated
2024-09-17 04:09 UTC
Primary CWE
CWE-502
CWE-502 Deserialization of Untrusted Data
Vendor / Product
Bosch / DIVAR IP 3000
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (3)
VendorProductPlatformVersions
Bosch BVMS Mobile Video Service unspecified ≤ 8.0.0.329, unspecified ≤ 9.0.0.827, unspecified ≤ 10.0.0.1225, unspecified ≤ 7.5
Bosch DIVAR IP 3000 All
Bosch DIVAR IP 7000 All
Weakness (CWE)
CWESourceDescription
CWE-502 cna CWE-502 Deserialization of Untrusted Data
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview