VYPR
High severity7.7NVD Advisory· Published Feb 6, 2020· Updated Jun 17, 2026

CVE-2020-6767

CVE-2020-6767

Description

A path traversal vulnerability in the Bosch Video Management System (BVMS) FileTransferService allows an authenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5 and older. This affects Bosch BVMS Viewer versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5 and older. This affects Bosch DIVAR IP 3000, DIVAR IP 7000 and DIVAR IP all-in-one 5000 if a vulnerable BVMS version is installed.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • cpe:2.3:a:bosch:video_management_system:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:bosch:video_management_system:*:*:*:*:*:*:*:*range: <=7.5
    • (no CPE)range: 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329, 7.5 and older
  • cpe:2.3:a:bosch:video_management_system_viewer:*:*:*:*:*:*:*:*
    Range: <=7.5
  • Range: 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329, 7.5 and older
  • Bosch/Divar IP 3000llm-fuzzy2 versions
    if a vulnerable BVMS version is installed+ 1 more
    • (no CPE)range: if a vulnerable BVMS version is installed
    • (no CPE)range: All

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.