RSS   Vulnerabilities for 'Video streaming gateway'   RSS

2021-03-25
 
CVE-2020-6790

CWE-427
 

 
Calling an executable through an Uncontrolled Search Path Element in the Bosch Video Streaming Gateway installer up to and including version 6.45.10 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious exe in the same directory where the installer is started from.

 
2020-02-07
 
CVE-2020-6769

CWE-306
 

 
Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote attacker to retrieve and set arbitrary configuration data of the Video Streaming Gateway. A successful attack can impact the confidentiality and availability of live and recorded video data of all cameras configured to be controlled by the VSG as well as the recording storage associated with the VSG. This affects Bosch Video Streaming Gateway versions 6.45 <= 6.45.08, 6.44 <= 6.44.022, 6.43 <= 6.43.0023 and 6.42.10 and older. This affects Bosch DIVAR IP 3000, DIVAR IP 7000 and DIVAR IP all-in-one 5000 if a vulnerable VSG version is installed with BVMS. This affects Bosch DIVAR IP 2000 <= 3.62.0019 and DIVAR IP 5000 <= 3.80.0039 if the corresponding port 8023 has been opened in the device's firewall.

 

 >>> Vendor: Bosch 16 Products
Smart camera
Bosch video management system
Building integration system
Access easy controller firmware
Dip 3000 firmware
Dip 7000 firmware
Access
Video recording manager
Bosch video management system mobile video service
Video management system viewer
Video streaming gateway
Smart home
Ip helper
Video client
Configuration manager
Monitor wall


Copyright 2021, cxsecurity.com

 

Back to Top