Vulnerabilities in Bosch

73 results
Vexday analysis

O portfólio de vulnerabilidades da Bosch apresenta um perfil de risco relativamente contido: nenhuma das 70 CVEs catalogadas figura no catálogo CISA KEV de explorações ativas, taxa abaixo da média geral do catálogo, e nenhum código de prova de conceito público foi identificado, o que reduz a exposição imediata a ataques oportunistas. Ainda assim, a presença de 9 vulnerabilidades de severidade crítica merece atenção contínua, especialmente em ambientes industriais e embarcados onde atualizações podem ser operacionalmente complexas. A CVE mais perigosa em evidência atualmente, CVE-2020-6779, apresenta EPSS de 0,037, indicando probabilidade de exploração baixa no curto prazo, mas sua antiguidade sugere que ambientes sem ciclos regulares de patching podem permanecer expostos. O tipo de falha mais recorrente, CWE-284 (controle de acesso impróprio), aponta para uma categoria de fraqueza estrutural que tende a impactar múltiplos componentes e requer revisão de arquitetura além de simples aplicação de patches.

CVE-2020-6779CRITICALHard-coded Credentials in the Database of Bosch FSM-2500 Server and Bosch FSM-5000 ServerEPSS 3.7%CVE-2020-6770CRITICALDeserialization of Untrusted Data in Bosch BVMS Mobile Video ServiceEPSS 3.6%CVE-2022-32534HIGHOS Command InjectionEPSS 2.3%CVE-2020-6769CRITICALMissing Authentication for Critical Function in Bosch Video Streaming GatewayEPSS 2.2%CVE-2019-11897HIGHServer-side request forgery in the backup & restore functionality of ProSyst mBS SDK and Bosch IoT Gateway SoftwareEPSS 1.8%CVE-2020-6768HIGHPath Traversal in Bosch Video Management System (BVMS)EPSS 1.7%CVE-2021-23851MEDIUMBuffer Overflow vulnerability in the recovery image web-based interfaceEPSS 1.5%CVE-2021-23850MEDIUMBuffer Overflow vulnerability in the recovery image telnet serverEPSS 1.5%CVE-2023-39509HIGHA command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administrative rights to run arbitrary cEPSS 1.5%CVE-2021-23847CRITICALUnauthenticated Information Extraction VulnerabilityEPSS 1.4%CVE-2021-23862HIGHAuthenticated Remote Code ExecutionEPSS 1.4%CVE-2020-6767HIGHPath Traversal in Bosch Video Management System (BVMS)EPSS 1.3%CVE-2024-25002HIGHCommand Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access to the device.EPSS 1.2%CVE-2019-11899HIGHAn unauthenticated attacker can achieve unauthorized access to sensitive data by exploiting Windows SMB protocol on a client installation. WEPSS 1.1%CVE-2019-11898CRITICALUnauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The service tool is discontiEPSS 1.1%CVE-2019-11892HIGHImproper access control in the JSON-RPC interface of the Bosch Smart Home Controller (SHC)EPSS 1.0%CVE-2019-11895MEDIUMImproper access control in the JSON-RPC interface of the Bosch Smart Home Controller (SHC)EPSS 1.0%CVE-2021-23859CRITICALDenial of Service and Authentication Bypass Vulnerability in multiple Bosch productsEPSS 1.0%CVE-2022-32536HIGHPrivilege EscalationEPSS 1.0%CVE-2022-36301CRITICALBF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device passwEPSS 0.9%