CVE-2019-11684
Bosch Video Recording Manager (VRM) vulnerability analysis and mitigation

Overview

The CVE-2019-11684 is a vulnerability affecting the RCP+ server of the Bosch Video Recording Manager (VRM) component. The vulnerability was discovered during internal product tests and disclosed on May 9, 2019. It affects VRM versions v3.70.x, v3.71 < v3.71.0034, v3.81 < 3.81.0050, DIVAR IP 5000 3.80 < 3.80.0039, and all versions of BVMS using VRM (Bosch Advisory).

Technical details

The vulnerability is classified as CWE-306 (Missing Authentication for Critical Function) and received a CVSS v3.1 base score of 9.8 (Critical) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The vulnerability allows arbitrary and unauthenticated access to a limited subset of certificates stored in the underlying Microsoft Windows operating system's certificate store (NVD, Bosch Advisory).

Impact

The vulnerability potentially allows unauthenticated access to a limited subset of certificates stored in the operating system's certificate store. The vulnerability is exploitable via the network interface and has been rated as Critical with a CVSSv3 score of 9.9 (Bosch Advisory).

Exploitability

As of May 9th, 2019, there was no indication that the vulnerability was either publicly known or being exploited in the wild. The vulnerability is exploitable through network access, requiring no authentication or user interaction (Bosch Advisory).

Mitigation and workarounds

Bosch recommends updating vulnerable components to fixed software versions. If immediate updates are not possible, mitigation measures include: reducing network exposure, implementing firewalls to prevent direct internet exposure, and utilizing IP filtering features. Systems should not be exposed directly to the internet, and port forwarding should be avoided. For shared environments, internal IP filters of BVMS Systems can be activated to whitelist specific IPs and IP-ranges (Bosch Advisory).

Additional resources


SourceThis report was generated using AI

Related Bosch Video Recording Manager (VRM) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-32230HIGH7.5
  • Bosch Video Recording Manager (VRM) logoBosch Video Recording Manager (VRM)
  • cpe:2.3:a:bosch:monitor_wall
NoNoDec 18, 2023
CVE-2021-23859HIGH7.5
  • Bosch Video Recording Manager (VRM) logoBosch Video Recording Manager (VRM)
  • cpe:2.3:a:bosch:building_integration_system
NoYesDec 08, 2021
CVE-2021-23862HIGH7.2
  • Bosch Video Recording Manager (VRM) logoBosch Video Recording Manager (VRM)
  • cpe:2.3:a:bosch:video_recording_manager
NoYesDec 08, 2021
CVE-2021-23861MEDIUM6.5
  • Bosch Video Recording Manager (VRM) logoBosch Video Recording Manager (VRM)
  • cpe:2.3:a:bosch:video_recording_manager
NoYesDec 08, 2021
CVE-2021-23860MEDIUM6.1
  • Bosch Video Recording Manager (VRM) logoBosch Video Recording Manager (VRM)
  • cpe:2.3:a:bosch:video_recording_manager
NoYesDec 08, 2021

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management