VYPR

Vendor CVEs

Bosch

All CVEs

149 total · sorted by risk
  • CVE-2015-6970CriFeb 18, 2020
    risk 0.67cvss 9.8epss 0.05

    The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to conduct XML injection attacks via the idstring parameter to rcp.xml.

  • CVE-2025-29902CriJun 13, 2025
    risk 0.65cvss 10.0epss 0.01

    Remote code execution that allows unauthorized users to execute arbitrary code on the server machine.

  • CVE-2021-23857CriOct 4, 2021
    risk 0.65cvss 10.0epss 0.01

    Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login to the system.

  • CVE-2021-23856CriOct 4, 2021
    risk 0.65cvss 10.0epss 0.01

    The web server is vulnerable to reflected XSS and therefore an attacker might be able to execute scripts on a client’s computer by sending the client a manipulated URL.

  • CVE-2020-6779CriJan 26, 2021
    risk 0.65cvss 10.0epss 0.04

    Use of Hard-coded Credentials in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows an unauthenticated remote attacker to log into the database with admin-privileges. This may result in complete compromise of the…

  • CVE-2020-6770CriFeb 7, 2020
    risk 0.65cvss 10.0epss 0.04

    Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on the system. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.0.329 and 7.5 and older. This…

  • CVE-2020-6769CriFeb 7, 2020
    risk 0.65cvss 10.0epss 0.02

    Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote attacker to retrieve and set arbitrary configuration data of the Video Streaming Gateway. A successful attack can impact the confidentiality and availability…

  • CVE-2022-36301CriAug 1, 2022
    risk 0.64cvss 9.8epss 0.01

    BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device password.

  • CVE-2021-23847CriJun 9, 2021
    risk 0.64cvss 9.8epss 0.01

    A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or change settings of the camera by sending crafted requests to the device. Only devices of the CPP6, CPP7 and CPP7.3 family with firmware…

  • CVE-2019-11684CriFeb 26, 2021
    risk 0.64cvss 9.9epss 0.01

    Improper Access Control in the RCP+ server of the Bosch Video Recording Manager (VRM) component allows arbitrary and unauthenticated access to a limited subset of certificates, stored in the underlying Microsoft Windows operating system. The fixed versions implement modified…

  • CVE-2019-11898CriSep 12, 2019
    risk 0.64cvss 9.9epss 0.01

    Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The service tool is discontinued with Bosch Access Professional Edition (APE) 3.8.

  • CVE-2019-6957CriMay 29, 2019
    risk 0.64cvss 9.8epss 0.02

    A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Video Recording Manager (VRM), Video Streaming Gateway (VSG), Configuration Manager, Building Integration System (BIS) with…

  • CVE-2018-20299CriDec 19, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firmware before 6.52.4. A malicious client could potentially succeed in the unauthorized execution of code on the device via the network interface, because there…

  • CVE-2018-19036CriDec 17, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in several Bosch IP cameras for firmware versions 6.32 and higher. A malicious client could potentially succeed in the unauthorized execution of code on the device via the network interface.

  • CVE-2025-32058CriFeb 15, 2026
    risk 0.60cvss 9.3epss 0.00

    The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment over the INC interface through a custom protocol. There is a vulnerability during processing requests of this protocol on the V850 side which allows an…

  • CVE-2020-6774CriMay 27, 2020
    risk 0.60cvss 9.3epss 0.00

    Improper Access Control in the Kiosk Mode functionality of Bosch Recording Station allows a local unauthenticated attacker to escape from the Kiosk Mode and access the underlying operating system.

  • CVE-2021-23859CriDec 8, 2021
    risk 0.59cvss 9.1epss 0.01

    An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM installation this crash also opens the possibility to send further unauthenticated commands to the service. On some products the…

  • CVE-2019-6958CriMay 29, 2019
    risk 0.59cvss 9.1epss 0.02

    A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Configuration Manager, Building Integration System (BIS) with Video Engine, Access Professional Edition (APE), Access Easy…

  • CVE-2025-32062HigFeb 15, 2026
    risk 0.57cvss 8.8epss 0.00

    The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a…

  • CVE-2025-32061HigFeb 15, 2026
    risk 0.57cvss 8.8epss 0.00

    The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a…

  • CVE-2025-32059HigFeb 15, 2026
    risk 0.57cvss 8.8epss 0.00

    The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a…

  • CVE-2025-24351HigApr 30, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the “Remote Logging” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to execute arbitrary OS commands in the context of user “root” via a crafted HTTP request.

  • CVE-2024-25002HigMar 25, 2024
    risk 0.57cvss 8.8epss 0.01

    Command Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access to the device.

  • CVE-2023-48253HigJan 10, 2024
    risk 0.57cvss 8.8epss 0.01

    The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication database via a crafted HTTP request. By abusing this vulnerability it is possible to exfiltrate other users’ password hashes or update them with arbitrary values…

  • CVE-2023-48252HigJan 10, 2024
    risk 0.57cvss 8.8epss 0.01

    The vulnerability allows an authenticated remote attacker to perform actions exceeding their authorized access via crafted HTTP requests.

  • CVE-2023-46102HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.00

    The Android Client application, when enrolled to the AppHub server, connects to an MQTT broker to exchange messages and receive commands to execute on the HMI device. The protocol builds on top of MQTT to implement the remote management of the device is encrypted with a…

  • CVE-2023-45851HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.00

    The Android Client application, when enrolled to the AppHub server,connects to an MQTT broker without enforcing any server authentication.  This issue allows an attacker to force the Android Client application to connect to a malicious MQTT broker, enabling it to send fake…

  • CVE-2023-45220HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.00

    The Android Client application, when enrolled with the define method 1(the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip address and credentials to connect to a remote MQTT broker entity) instead of HTTPS and this feature…

  • CVE-2023-41255HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.00

    The vulnerability allows an unprivileged user with access to the subnet of the TPC-110W device to gain a root shell on the device itself abusing the lack of authentication of the ‘su’ binary file installed on the device that can be accessed through the ADB (Android Debug…

  • CVE-2022-36302HigAug 1, 2022
    risk 0.57cvss 8.8epss 0.01

    File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access different resources, which may contain sensitive information.

  • CVE-2022-32536HigJun 23, 2022
    risk 0.57cvss 8.8epss 0.01

    The user access rights validation in the web server of the Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 was insufficient. This would allow a non-administrator user to obtain administrator user access rights.

  • CVE-2022-32534HigJun 23, 2022
    risk 0.57cvss 8.8epss 0.02

    The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command injection through its diagnostics web interface. This allows execution of shell commands.

  • CVE-2021-23843HigJan 19, 2022
    risk 0.57cvss 8.8epss 0.00

    The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a password protection on configured devices to restrict access to the configuration of an AMC2. An attacker can circumvent this…

  • CVE-2021-23846HigJun 18, 2021
    risk 0.57cvss 8.8epss 0.01

    When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5, which will be released on the 30th of June, 2021.

  • CVE-2020-6776HigJan 14, 2021
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAESENSA until and including version 1.10 allows an unauthenticated remote attacker to trigger actions on an affected system on behalf of another user (Cross-Site…

  • CVE-2021-23858HigOct 4, 2021
    risk 0.56cvss 8.6epss 0.01

    Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware…

  • CVE-2021-23855HigOct 4, 2021
    risk 0.56cvss 8.6epss 0.01

    The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashing algorithm and therefore allow an attacker to determine the password by using rainbow tables.

  • CVE-2020-6768HigFeb 7, 2020
    risk 0.56cvss 8.6epss 0.02

    A path traversal vulnerability in the Bosch Video Management System (BVMS) NoTouch deployment allows an unauthenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5…

  • CVE-2019-11897HigAug 21, 2019
    risk 0.56cvss 8.6epss 0.02

    A Server-Side Request Forgery (SSRF) vulnerability in the backup & restore functionality in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.3.0 allows a remote attacker to forge GET requests to arbitrary URLs. In addition, this could potentially…

  • CVE-2023-34999HigSep 18, 2023
    risk 0.55cvss 8.4epss 0.01

    A command injection vulnerability exists in RTS VLink Virtual Matrix Software Versions v5 (< 5.7.6) and v6 (< 6.5.0) that allows an attacker to perform arbitrary code execution via the admin web interface.

  • CVE-2023-49722HigJan 9, 2024
    risk 0.54cvss 8.3epss 0.00

    Network port 8899 open in WiFi firmware of BCC101/BCC102/BCC50 products, that allows an attacker to connect to the device via same WiFi network.

  • CVE-2023-45321HigOct 25, 2023
    risk 0.54cvss 8.3epss 0.00

    The Android Client application, when enrolled with the define method 1 (the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip address and credentials to connect to a remote MQTT broker entity) instead of HTTPS and this feature…

  • CVE-2021-23854HigJun 9, 2021
    risk 0.54cvss 8.3epss 0.01

    An error in the handling of a page parameter in Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. This issue only affects versions 7.7x and 7.6x. All other versions are not affected.

  • CVE-2021-23853HigJun 9, 2021
    risk 0.54cvss 8.3epss 0.01

    In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP headers through crafted URLs.

  • CVE-2021-23848HigJun 9, 2021
    risk 0.54cvss 8.3epss 0.01

    An error in the URL handler Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the camera address can send a crafted link to a user, which will execute javascript code in the context of the user.

  • CVE-2023-48266HigJan 10, 2024
    risk 0.53cvss 8.1epss 0.01

    The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

  • CVE-2023-48265HigJan 10, 2024
    risk 0.53cvss 8.1epss 0.01

    The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

  • CVE-2023-48264HigJan 10, 2024
    risk 0.53cvss 8.1epss 0.01

    The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

  • CVE-2023-48263HigJan 10, 2024
    risk 0.53cvss 8.1epss 0.01

    The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

  • CVE-2023-48262HigJan 10, 2024
    risk 0.53cvss 8.1epss 0.01

    The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.

Page 1 of 3