← Back

CVE-2020-6785

nvd nist
Published: Mar 25, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Loading a DLL through an Uncontrolled Search Path Element in Bosch BVMS and BVMS Viewer in versions 10.1.0, 10.0.1, 10.0.0 and 9.0.0 and older potentially allows an attacker to execute arbitrary code on a victim's system. This affects both the installer as well as the installed application. This also affects Bosch DIVAR IP 7000 R2, Bosch DIVAR IP all-in-one 5000 and Bosch DIVAR IP all-in-one 7000 with installers and installed BVMS versions prior to BVMS 10.1.1.

Affected (6)

2 products
Video Management System
Video Management System Viewer
Configuration A
1 platform
Running on/withPlatform Versions
Bosch
Divar Ip 7000 R2
All versions
Configuration B
1 platform
Running on/withPlatform Versions
Bosch
Divar Ip All In One 5000
All versions
Configuration C
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Bosch
Before 9.0
From 10.0 to 10.0.2
From 10.1 to 10.1.1
Running on/withPlatform Versions
Bosch
Divar Ip All In One 7000
All versions
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Bosch
Before 9.0
From 10.0 to 10.0.2
From 10.1.0 to 10.1.1

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.