VYPR
Medium severity5.9NVD Advisory· Published Sep 30, 2022· Updated Jun 17, 2026

CVE-2022-32540

CVE-2022-32540

Description

Information Disclosure in Operator Client application in BVMS 10.1.1, 11.0 and 11.1.0 and VIDEOJET Decoder VJD-7513 versions 10.23 and 10.30 allows man-in-the-middle attacker to compromise confidential video stream. This is only applicable for UDP encryption when target system contains cameras with platform CPP13 or CPP14 and firmware version 8.x.

Affected products

8
  • cpe:2.3:a:bosch:bosch_video_management_system:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:bosch:bosch_video_management_system:*:*:*:*:*:*:*:*range: >=10.1,<=10.1.1
    • cpe:2.3:a:bosch:bosch_video_management_system:11.0:*:*:*:*:*:*:*
  • cpe:2.3:o:bosch:videojet_decoder_7513_firmware:10.23.0002:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:bosch:videojet_decoder_7513_firmware:10.23.0002:*:*:*:*:*:*:*
    • cpe:2.3:o:bosch:videojet_decoder_7513_firmware:10.30.0005:*:*:*:*:*:*:*
  • Bosch/BVMSllm-fuzzy2 versions
    10.1.1, 11.0, 11.1.0+ 1 more
    • (no CPE)range: 10.1.1, 11.0, 11.1.0
    • (no CPE)range: 11.1
  • Range: 10.23, 10.30
  • Bosch/VJD-7513v5
    Range: 10.23.0002

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.