CVE-2020-6785
Bosch Video Management System (BVMS) vulnerability analysis and mitigation

Overview

CVE-2020-6785 is a security vulnerability affecting Bosch BVMS and BVMS Viewer in versions 10.1.0, 10.0.1, 10.0.0, and 9.0.0 and older. The vulnerability was disclosed on March 24, 2021, and involves an Uncontrolled Search Path Element that affects both the installer and installed application. The vulnerability also impacts Bosch DIVAR IP 7000 R2, Bosch DIVAR IP all-in-one 5000, and Bosch DIVAR IP all-in-one 7000 with installers and installed BVMS versions prior to BVMS 10.1.1 (Bosch Advisory).

Technical details

The vulnerability is classified as CWE-427 (Uncontrolled Search Path Element) with a CVSS v3.1 Base Score of 7.8 (High). The CVSS vector string is CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating local access, low attack complexity, no privileges required, user interaction required, and high impact on confidentiality, integrity, and availability (Bosch Advisory).

Impact

The vulnerability potentially allows an attacker to execute arbitrary code on a victim's system through DLL loading (commonly known as 'DLL Hijacking' or 'DLL Preloading'). The code is executed during the start of the vulnerable application and in the context of the user (Bosch Advisory).

Exploitability

Exploitation requires local access and user interaction. The attacker must trick the victim into placing a malicious DLL in the same directory where the installer is started from or where the application is installed (Bosch Advisory).

Mitigation and workarounds

Bosch recommends using updated installers for (re)installations and updating to the latest versions of portable applications. For BVMS and BVMS Viewer, customers should completely update the installed product to the latest version. The fixed versions include BVMS 10.1.1 Technical Update for version 10.1.0, BVMS 10.0.2 Technical Update for versions 10.0.1 and 10.0.0. For versions 9.0.0 and older, users should upgrade to the latest BVMS version (Bosch Advisory).

Additional resources


SourceThis report was generated using AI

Related Bosch Video Management System (BVMS) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2019-11684CRITICAL9.8
  • Bosch Video Recording Manager (VRM) logoBosch Video Recording Manager (VRM)
  • cpe:2.3:a:bosch:video_management_system
NoYesFeb 26, 2021
CVE-2020-6785HIGH7.8
  • Bosch Video Management System (BVMS) logoBosch Video Management System (BVMS)
  • cpe:2.3:a:bosch:video_management_system
NoYesMar 25, 2021
CVE-2023-28175HIGH7.7
  • Bosch Video Management System (BVMS) logoBosch Video Management System (BVMS)
  • cpe:2.3:a:bosch:video_management_system
NoNoJun 15, 2023
CVE-2020-6768HIGH7.5
  • Bosch Video Management System (BVMS) logoBosch Video Management System (BVMS)
  • cpe:2.3:a:bosch:video_management_system
NoYesFeb 07, 2020
CVE-2020-6767MEDIUM6.5
  • Bosch Video Management System (BVMS) logoBosch Video Management System (BVMS)
  • cpe:2.3:a:bosch:video_management_system
NoYesFeb 06, 2020

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management