High severity7.7NVD Advisory· Published Feb 6, 2020· Updated Jun 17, 2026
CVE-2020-6767
CVE-2020-6767
Description
A path traversal vulnerability in the Bosch Video Management System (BVMS) FileTransferService allows an authenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5 and older. This affects Bosch BVMS Viewer versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5 and older. This affects Bosch DIVAR IP 3000, DIVAR IP 7000 and DIVAR IP all-in-one 5000 if a vulnerable BVMS version is installed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:bosch:video_management_system:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:bosch:video_management_system:*:*:*:*:*:*:*:*range: <=7.5
- (no CPE)range: 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329, 7.5 and older
- cpe:2.3:a:bosch:video_management_system_viewer:*:*:*:*:*:*:*:*Range: <=7.5
- Range: 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329, 7.5 and older
if a vulnerable BVMS version is installed+ 1 more
- (no CPE)range: if a vulnerable BVMS version is installed
- (no CPE)range: All
- Range: All
Patches
Vulnerability mechanics
References
2- media.boschsecurity.com/fs/media/pb/security_advisories/bosch-sa-381489-bt_cve-2020-6767_securityadvisory_bvms_pathtraversal.pdfnvdPatchVendor Advisory
- psirt.bosch.com/security-advisories/BOSCH-SA-381489-BT.htmlnvdBroken LinkVendor Advisory
News mentions
0No linked articles in our index yet.