High severity7.1NVD Advisory· Published Jun 15, 2023· Updated Jun 17, 2026
CVE-2023-28175
CVE-2023-28175
Description
Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access resources within the trusted internal network via a port forwarding request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
20- cpe:2.3:a:bosch:video_management_system:*:*:*:*:*:*:*:*Range: >=7.5,<=11.1.1
- cpe:2.3:a:bosch:video_management_system_viewer:*:*:*:*:*:*:*:*Range: >=7.5,<=11.1.1
- cpe:2.3:o:bosch:divar_ip_3000_firmware:*:*:*:*:*:*:*:*Range: >=7.5,<=8.0
- cpe:2.3:o:bosch:divar_ip_4000_firmware:11.1.1:*:*:*:*:*:*:*
- cpe:2.3:o:bosch:divar_ip_5000_firmware:*:*:*:*:*:*:*:*Range: >=9.0,<=11.1.1
- cpe:2.3:o:bosch:divar_ip_6000_firmware:11.1.1:*:*:*:*:*:*:*
- cpe:2.3:o:bosch:divar_ip_7000_firmware:*:*:*:*:*:*:*:*Range: >=7.5,<=8.0
- cpe:2.3:o:bosch:divar_ip_7000_r2_firmware:*:*:*:*:*:*:*:*Range: >=7.5,<=11.1.1
- cpe:2.3:o:bosch:divar_ip_7000_r3_firmware:*:*:*:*:*:*:*:*Range: >=10.1.1,<=11.1.1
- Range: 7.5
- Bosch/Bosch DIVAR IP 7000 R1v5Range: 7.5
- Bosch/Bosch DIVAR IP 7000 R2v5Range: 7.5
9.0+ 4 more
- (no CPE)range: 9.0
- (no CPE)range: 9.0
- (no CPE)range: 10.1.1
- (no CPE)range: 11.1.1
- (no CPE)range: 11.1.1
- Range: 7.5
Patches
Vulnerability mechanics
References
1- psirt.bosch.com/security-advisories/BOSCH-SA-025794-bt.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.