← Back

CVE-2019-11684

nvd nist
Published: Feb 26, 2021Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Improper Access Control in the RCP+ server of the Bosch Video Recording Manager (VRM) component allows arbitrary and unauthenticated access to a limited subset of certificates, stored in the underlying Microsoft Windows operating system. The fixed versions implement modified authentication checks. Prior releases of VRM software version 3.70 are considered unaffected. This vulnerability affects VRM v3.70.x, v3.71 < v3.71.0034 and v3.81 < 3.81.0050; DIVAR IP 5000 3.80 < 3.80.0039; BVMS all versions using VRM.

Affected (14)

3 products
Video Recording Manager
Divar Ip 5000 Firmware
Video Management System
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Bosch
From 3.70 to 3.71.0034
From 3.81 to 3.81.0050
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 3.80 to 3.80.0039
Running on/withPlatform Versions
Bosch
Divar Ip 5000
All versions
Configuration C
11 vulnerable
Vulnerable SoftwareAffected Versions
Bosch
Version 3.70.0056
Version 3.70.0058
Version 3.70.0060
Version 3.70.0062
Version 3.71.0022
Version 3.71.0029
Version 3.71.0031
Version 3.71.0032
Version 3.81.0032
Version 3.81.0038
Version 3.81.0048

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.