Bosch
bosch
108 CVEs • 347 products
Products (347)
Click to collapseToggle
Products (347)
Click to collapse
CVEs (108)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Bosch 1Videojet Multi 4000 Firmware Jun 17, 2026 Oct 27, 2022 N/A· v4 4.7 MEDIUM· v3 N/A· v2 An error in the URL handler of the VIDEOJET multi 4000 may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the encoder address can send a crafted link to a user, w...Show more |
1Bosch 2Bosch Video Management System Videojet Decoder 7513 FirmwareJun 17, 2026 Sep 30, 2022 N/A· v4 5.9 MEDIUM· v3 N/A· v2 Information Disclosure in Operator Client application in BVMS 10.1.1, 11.0 and 11.1.0 and VIDEOJET Decoder VJD-7513 versions 10.23 and 10.30 allows man-in-the-middle attacker to compromise confidential video stream. This...Show more |
File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access different resources, which may contain sensitive information. |
BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device password. |
The user access rights validation in the web server of the Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 was insufficient. This would allow a non-administrator user to obtain administrator user access ri...Show more |
1Bosch 1Pra Es8p2s Firmware Jun 17, 2026 Jun 23, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 runs its web server with root privilege. In combination with CVE-2022-23534 this could give an attacker root access to the switch. |
1Bosch 1Pra Es8p2s Firmware Jun 17, 2026 Jun 23, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command injection through its diagnostics web interface. This allows execution of shell commands. |
1Bosch 68Autodome 7000 Firmware Autodome Ip 4000 Hd FirmwareAutodome Ip 4000i Firmware+65 moreJun 17, 2026 Mar 30, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with admin...Show more |
1Bosch 68Autodome 7000 Firmware Autodome Ip 4000 Hd FirmwareAutodome Ip 4000i Firmware+65 moreJun 17, 2026 Mar 30, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A specially crafted TCP/IP packet may cause a camera recovery image telnet interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with admi...Show more |
HTML code injection vulnerability in Android Application, Bosch Video Security, version 3.2.3. or earlier, when successfully exploited allows an attacker to inject random HTML code into a component loaded by WebView, thu...Show more |
1Bosch 4Access Management System Access Professional EditionAmc2 Firmware+1 moreJun 17, 2026 Jan 19, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a password protection on configured devices to restrict access to the confi...Show more |
1Bosch 4Access Management System Access Professional EditionAmc2 Firmware+1 moreJun 17, 2026 Jan 19, 2022 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An attacker could retrieve the key from the firmware to decrypt network traffic between the AMC2 and the...Show more |
1Bosch 4Bosch Video Management System Video Recording ManagerVideojet Decoder 7513 Firmware+1 moreJun 17, 2026 Dec 8, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in system context. This issue also affects installations of the VRM, DIVAR IP, BVMS with VRM installed...Show more |
1Bosch 2Bosch Video Management System Video Recording ManagerJun 17, 2026 Dec 8, 2021 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 By executing a special command, an user with administrative rights can get access to extended debug functionality on the VRM allowing an impact on integrity or availability of the installed software. This issue also affe...Show more |
1Bosch 2Bosch Video Management System Video Recording ManagerJun 17, 2026 Dec 8, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An error in a page handler of the VRM may lead to a reflected cross site scripting (XSS) in the web-based interface. To exploit this vulnerability an attack must be able to modify the HTTP header that is sent. This issue...Show more |
1Bosch 6Access Easy Controller Firmware Access Professional EditionBosch Video Management System+3 moreJun 17, 2026 Dec 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM installation this crash also opens the possibility to send further unauthen...Show more |
1Bosch 12Indracontrol Xlc Firmware Rexroth Indramotion Mlc L20 FirmwareRexroth Indramotion Mlc L25 Firmware+9 moreJun 17, 2026 Oct 4, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are ex...Show more |
1Bosch 12Rexroth Indramotion Mlc L20 Firmware Rexroth Indramotion Mlc L25 FirmwareRexroth Indramotion Mlc L40 Firmware+9 moreJun 17, 2026 Oct 4, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login t...Show more |
1Bosch 2Rexroth Indramotion Mlc L20 Firmware Rexroth Indramotion Mlc L40 FirmwareJun 17, 2026 Oct 4, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The web server is vulnerable to reflected XSS and therefore an attacker might be able to execute scripts on a client’s computer by sending the client a manipulated URL. |
1Bosch 2Rexroth Indramotion Mlc Firmware Rexroth Indramotion Xlc FirmwareJun 17, 2026 Oct 4, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashing algorithm and therefore allow an attacker to determine the password by using rainbow tables. |