← Back

CVE-2020-6767

nvd nist
Published: Feb 6, 2020Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A path traversal vulnerability in the Bosch Video Management System (BVMS) FileTransferService allows an authenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5 and older. This affects Bosch BVMS Viewer versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5 and older. This affects Bosch DIVAR IP 3000, DIVAR IP 7000 and DIVAR IP all-in-one 5000 if a vulnerable BVMS version is installed.

Affected (8)

2 products
Video Management System Viewer
Video Management System
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Bosch
Up to 7.5
From 10.0 to 10.0.0.1225
From 8.0 to 8.0.329
From 9.0 to 9.0.0.827
Configuration B
1 platform
Running on/withPlatform Versions
Bosch
Divar Ip 3000
All versions
Configuration C
1 platform
Running on/withPlatform Versions
Bosch
Divar Ip 7000
All versions
Configuration D
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Bosch
Up to 7.5
From 10.0 to 10.0.0.1225
From 8.0 to 8.0.0.329
From 9.0 to 9.0.0.827
Running on/withPlatform Versions
Bosch
Divar Ip All In One 5000
All versions

Timeline

No history available yet.