VYPR
Vendor

Bosch

Products
240
CVEs
149
Across products
225
Status
Private

Products

240
View all 240 products →

Recent CVEs

149
View all 149 CVEs →
  • CVE-2015-6970CriFeb 18, 2020
    risk 0.67cvss 9.8epss 0.05

    The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to conduct XML injection attacks via the idstring parameter to rcp.xml.

  • CVE-2025-29902CriJun 13, 2025
    risk 0.65cvss 10.0epss 0.01

    Remote code execution that allows unauthorized users to execute arbitrary code on the server machine.

  • CVE-2021-23857CriOct 4, 2021
    risk 0.65cvss 10.0epss 0.01

    Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login to the system.

  • CVE-2021-23856CriOct 4, 2021
    risk 0.65cvss 10.0epss 0.01

    The web server is vulnerable to reflected XSS and therefore an attacker might be able to execute scripts on a client’s computer by sending the client a manipulated URL.

  • CVE-2020-6779CriJan 26, 2021
    risk 0.65cvss 10.0epss 0.04

    Use of Hard-coded Credentials in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows an unauthenticated remote attacker to log into the database with admin-privileges. This may result in complete compromise of the…

  • CVE-2020-6770CriFeb 7, 2020
    risk 0.65cvss 10.0epss 0.04

    Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on the system. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.0.329 and 7.5 and older. This…

  • CVE-2020-6769CriFeb 7, 2020
    risk 0.65cvss 10.0epss 0.02

    Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote attacker to retrieve and set arbitrary configuration data of the Video Streaming Gateway. A successful attack can impact the confidentiality and availability…

  • CVE-2022-36301CriAug 1, 2022
    risk 0.64cvss 9.8epss 0.01

    BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device password.

  • CVE-2021-23847CriJun 9, 2021
    risk 0.64cvss 9.8epss 0.01

    A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or change settings of the camera by sending crafted requests to the device. Only devices of the CPP6, CPP7 and CPP7.3 family with firmware…

  • CVE-2019-11684CriFeb 26, 2021
    risk 0.64cvss 9.9epss 0.01

    Improper Access Control in the RCP+ server of the Bosch Video Recording Manager (VRM) component allows arbitrary and unauthenticated access to a limited subset of certificates, stored in the underlying Microsoft Windows operating system. The fixed versions implement modified…

  • CVE-2019-11898CriSep 12, 2019
    risk 0.64cvss 9.9epss 0.01

    Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The service tool is discontinued with Bosch Access Professional Edition (APE) 3.8.

  • CVE-2019-6957CriMay 29, 2019
    risk 0.64cvss 9.8epss 0.02

    A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Video Recording Manager (VRM), Video Streaming Gateway (VSG), Configuration Manager, Building Integration System (BIS) with…

  • CVE-2018-20299CriDec 19, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firmware before 6.52.4. A malicious client could potentially succeed in the unauthorized execution of code on the device via the network interface, because there…

  • CVE-2018-19036CriDec 17, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in several Bosch IP cameras for firmware versions 6.32 and higher. A malicious client could potentially succeed in the unauthorized execution of code on the device via the network interface.

  • CVE-2025-32058CriFeb 15, 2026
    risk 0.60cvss 9.3epss 0.00

    The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment over the INC interface through a custom protocol. There is a vulnerability during processing requests of this protocol on the V850 side which allows an…

  • CVE-2020-6774CriMay 27, 2020
    risk 0.60cvss 9.3epss 0.00

    Improper Access Control in the Kiosk Mode functionality of Bosch Recording Station allows a local unauthenticated attacker to escape from the Kiosk Mode and access the underlying operating system.

  • CVE-2021-23859CriDec 8, 2021
    risk 0.59cvss 9.1epss 0.01

    An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM installation this crash also opens the possibility to send further unauthenticated commands to the service. On some products the…

  • CVE-2019-6958CriMay 29, 2019
    risk 0.59cvss 9.1epss 0.02

    A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Configuration Manager, Building Integration System (BIS) with Video Engine, Access Professional Edition (APE), Access Easy…

  • CVE-2025-32062HigFeb 15, 2026
    risk 0.57cvss 8.8epss 0.00

    The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a…

  • CVE-2025-32061HigFeb 15, 2026
    risk 0.57cvss 8.8epss 0.00

    The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a…