Bosch
bosch
108 CVEs • 347 products
Products (347)
Click to collapseToggle
Products (347)
Click to collapse
CVEs (108)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Bosch 7Aviotec Firmware Cpp13 FirmwareCpp14 Firmware+4 moreJun 17, 2026 Aug 5, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A vulnerability in the web-based interface allows an unauthenticated remote attacker to trigger actions on an affected system on behalf of another user (CSRF - Cross Site Request Forgery). This requires the victim to be...Show more |
When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5,...Show more |
1Bosch 4B426 Cn Firmware B426 M FirmwareB426 Firmware+1 moreJun 17, 2026 Jun 18, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 This vulnerability could allow an attacker to hijack a session while a user is logged in the configuration web page. This vulnerability was discovered by a security researcher in B426 and found during internal product te...Show more |
1Bosch 4Cpp13 Firmware Cpp6 FirmwareCpp7.3 Firmware+1 moreJun 17, 2026 Jun 9, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An error in the handling of a page parameter in Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. This issue only affects versions 7.7x and 7.6x. All other versions are not a...Show more |
1Bosch 5Cpp13 Firmware Cpp4 FirmwareCpp6 Firmware+2 moreJun 17, 2026 Jun 9, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP headers through crafted URLs. |
1Bosch 5Cpp13 Firmware Cpp4 FirmwareCpp6 Firmware+2 moreJun 17, 2026 Jun 9, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 An authenticated attacker with administrator rights Bosch IP cameras can call an URL with an invalid parameter that causes the camera to become unresponsive for a few seconds and cause a Denial of Service (DoS). |
1Bosch 5Cpp13 Firmware Cpp4 FirmwareCpp6 Firmware+2 moreJun 17, 2026 Jun 9, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An error in the URL handler Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the camera address can send a crafted link to a user, which will e...Show more |
1Bosch 3Cpp6 Firmware Cpp7.3 FirmwareCpp7 FirmwareJun 17, 2026 Jun 9, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or change settings of the camera by sending crafted requests to the device. Onl...Show more |
1Bosch 1Video Streaming Gateway Jun 17, 2026 Mar 25, 2021 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 Calling an executable through an Uncontrolled Search Path Element in the Bosch Video Streaming Gateway installer up to and including version 6.45.10 potentially allows an attacker to execute arbitrary code on a victim's...Show more |
Loading a DLL through an Uncontrolled Search Path Element in the Bosch Monitor Wall installer up to and including version 10.00.0164 potentially allows an attacker to execute arbitrary code on a victim's system. A prereq...Show more |
Loading a DLL through an Uncontrolled Search Path Element in the Bosch Configuration Manager installer up to and including version 7.21.0078 potentially allows an attacker to execute arbitrary code on a victim's system....Show more |
Loading a DLL through an Uncontrolled Search Path Element in the Bosch Video Client installer up to and including version 1.7.6.079 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequ...Show more |
1Bosch 1Video Recording Manager Jun 17, 2026 Mar 25, 2021 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 Loading a DLL through an Uncontrolled Search Path Element in the Bosch Video Recording Manager installer up to and including version 3.82.0055 for 3.82, up to and including version 3.81.0064 for 3.81 and 3.71 and older p...Show more |
1Bosch 2Video Management System Video Management System ViewerJun 17, 2026 Mar 25, 2021 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 Loading a DLL through an Uncontrolled Search Path Element in Bosch BVMS and BVMS Viewer in versions 10.1.0, 10.0.1, 10.0.0 and 9.0.0 and older potentially allows an attacker to execute arbitrary code on a victim's system...Show more |
Loading a DLL through an Uncontrolled Search Path Element in Bosch IP Helper up to and including version 1.00.0008 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the...Show more |
1Bosch 3Divar Ip 5000 Firmware Video Management SystemVideo Recording ManagerJun 17, 2026 Feb 26, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Improper Access Control in the RCP+ server of the Bosch Video Recording Manager (VRM) component allows arbitrary and unauthenticated access to a limited subset of certificates, stored in the underlying Microsoft Windows...Show more |
1Bosch 2Fsm 2500 Firmware Fsm 5000 FirmwareJun 17, 2026 Jan 26, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Use of Password Hash With Insufficient Computational Effort in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows a remote attacker with admin privileges to dump the cr...Show more |
1Bosch 2Fsm 2500 Firmware Fsm 5000 FirmwareJun 17, 2026 Jan 26, 2021 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 Use of Hard-coded Credentials in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows an unauthenticated remote attacker to log into the database with admin-privileges. T...Show more |
1Bosch 2Praesensa Firmware Praesideo FirmwareJun 17, 2026 Jan 14, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAESENSA until and including version 1.10 allows an authenticated remote attacker with admin privileges...Show more |
1Bosch 2Praesensa Firmware Praesideo FirmwareJun 17, 2026 Jan 14, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAESENSA until and including version 1.10 allows an unauthenticated remote attacker to trigger actions...Show more |