Vulnerabilities > Bosch

DATE CVE VULNERABILITY TITLE RISK
2023-09-18 CVE-2023-34999 Command Injection vulnerability in Bosch RTS Vlink Virtual Matrix 5.0.0/6.0.0
A command injection vulnerability exists in RTS VLink Virtual Matrix Software Versions v5 (< 5.7.6) and v6 (< 6.5.0) that allows an attacker to perform arbitrary code execution via the admin web interface.
network
low complexity
bosch CWE-77
7.2
2023-06-30 CVE-2023-29241 Unspecified vulnerability in Bosch Building Integration System 5.0
Improper Information in Cybersecurity Guidebook in Bosch Building Integration System (BIS) 5.0 may lead to wrong configuration which allows local users to access data via network
local
low complexity
bosch
7.1
2023-06-15 CVE-2023-28175 Incorrect Authorization vulnerability in Bosch products
Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access resources within the trusted internal network via a port forwarding request.
network
low complexity
bosch CWE-863
7.7
2023-06-15 CVE-2023-32229 Resource Exhaustion vulnerability in Bosch Cpp13 Firmware and Cpp14 Firmware
Due to an error in the software interface to the secure element chip on Bosch IP cameras of family CPP13 and CPP14, the chip can be permanently damaged when enabling the Stream security option (signing of the video stream) with option MD5, SHA-1 or SHA-256.
network
low complexity
bosch CWE-400
6.5
2023-02-08 CVE-2022-47648 Authentication Bypass by Spoofing vulnerability in Bosch B420 Firmware 02.02.0001
An Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring any sort of authorization or authentication due to the IP based authorization.
low complexity
bosch CWE-290
8.8
2022-10-27 CVE-2022-40183 Cross-site Scripting vulnerability in Bosch Videojet Multi 4000 Firmware
An error in the URL handler of the VIDEOJET multi 4000 may lead to a reflected cross site scripting (XSS) in the web-based interface.
network
high complexity
bosch CWE-79
4.7
2022-10-27 CVE-2022-40184 Cross-site Scripting vulnerability in Bosch Videojet Multi 4000 Firmware
Incomplete filtering of JavaScript code in different configuration fields of the web based interface of the VIDEOJET multi 4000 allows an attacker with administrative credentials to store JavaScript code which will be executed for all administrators accessing the same configuration option.
network
low complexity
bosch CWE-79
4.8
2022-09-30 CVE-2022-32540 Information Exposure vulnerability in Bosch products
Information Disclosure in Operator Client application in BVMS 10.1.1, 11.0 and 11.1.0 and VIDEOJET Decoder VJD-7513 versions 10.23 and 10.30 allows man-in-the-middle attacker to compromise confidential video stream.
network
high complexity
bosch CWE-200
5.9
2022-08-01 CVE-2022-36301 Weak Password Requirements vulnerability in Bosch Bf-Os
BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device password.
network
low complexity
bosch CWE-521
7.5
2022-08-01 CVE-2022-36302 Injection vulnerability in Bosch Bf-Os
File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access different resources, which may contain sensitive information.
network
low complexity
bosch CWE-74
5.4