Vulnerabilities in Bosch

73 results
Vexday analysis

O portfólio de vulnerabilidades da Bosch apresenta um perfil de risco relativamente contido: nenhuma das 70 CVEs catalogadas figura no catálogo CISA KEV de explorações ativas, taxa abaixo da média geral do catálogo, e nenhum código de prova de conceito público foi identificado, o que reduz a exposição imediata a ataques oportunistas. Ainda assim, a presença de 9 vulnerabilidades de severidade crítica merece atenção contínua, especialmente em ambientes industriais e embarcados onde atualizações podem ser operacionalmente complexas. A CVE mais perigosa em evidência atualmente, CVE-2020-6779, apresenta EPSS de 0,037, indicando probabilidade de exploração baixa no curto prazo, mas sua antiguidade sugere que ambientes sem ciclos regulares de patching podem permanecer expostos. O tipo de falha mais recorrente, CWE-284 (controle de acesso impróprio), aponta para uma categoria de fraqueza estrutural que tende a impactar múltiplos componentes e requer revisão de arquitetura além de simples aplicação de patches.

CVE-2021-23849HIGHCross Site Request Forgery (CSRF) vulnerability in web based management interfaceEPSS 0.5%CVE-2021-23846HIGHB426 Credential DisclosureEPSS 0.5%CVE-2023-28175HIGHImproper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access resources within theEPSS 0.5%CVE-2024-33618HIGHUncontrolled Resource Consumption in Bosch VMS Central Server in Bosch VMS 12.0.1 allows attackers to consume excessive amounts of disk spEPSS 0.5%CVE-2020-6781MEDIUMImproper Certificate Validation in Bosch Smart Home System App for iOSEPSS 0.5%CVE-2019-11893MEDIUMIncorrect privilege assignment in the app permission update API of the Bosch Smart Home Controller (SHC)EPSS 0.4%CVE-2023-49722HIGHNetwork port 8899 open in WiFi firmware of BCC101/BCC102/BCC50 products, that allows an attacker to connect to the device via same WiFi netwEPSS 0.4%CVE-2022-47648HIGHAn Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring any sort of authorizatEPSS 0.4%CVE-2025-32059HIGHStack Buffer Overflow leading to RCE in Bluetooth stack of Infotainment ECUEPSS 0.4%CVE-2025-32061HIGHStack Buffer Overflow leading to RCE in Bluetooth stack of Infotainment ECUEPSS 0.4%CVE-2025-32062HIGHStack Buffer Overflow leading to RCE in Bluetooth stack of Infotainment ECUEPSS 0.4%CVE-2023-29241HIGHImproper Information in Cybersecurity Guidebook in Bosch Building Integration System (BIS) 5.0 may lead to wrong configuration which allows EPSS 0.4%CVE-2020-6786HIGHUncontrolled Search Path Element in Bosch Video Recording Manager InstallerEPSS 0.3%CVE-2020-6771HIGHUncontrolled Search Path Element in Bosch IP HelperEPSS 0.3%CVE-2020-6787HIGHUncontrolled Search Path Element in Bosch Video Client installerEPSS 0.3%CVE-2020-6789HIGHUncontrolled Search Path Element in Bosch Monitor Wall InstallerEPSS 0.3%CVE-2020-6790HIGHUncontrolled Search Path Element in Bosch Video Streaming Gateway InstallerEPSS 0.3%CVE-2020-6788HIGHUncontrolled Search Path Element in Bosch Configuration Manager InstallerEPSS 0.3%CVE-2022-40183MEDIUMReflected Cross Site Scripting (XSS) in VIDEOJET multi 4000EPSS 0.3%CVE-2022-32540HIGHInformation Disclosure in Operator Client application in BVMS 10.1.1, 11.0 and 11.1.0 and VIDEOJET Decoder VJD-7513 versions 10.23 and 10.30EPSS 0.3%