CVE-2020-6789
Bosch Monitor Wall vulnerability analysis and mitigation

Overview

CVE-2020-6789 is a security vulnerability affecting the Bosch Monitor Wall installer up to and including version 10.00.0164. The vulnerability is classified as an Uncontrolled Search Path Element issue that could potentially allow an attacker to execute arbitrary code on a victim's system through DLL loading (Bosch PSIRT). The vulnerability was discovered and disclosed to Bosch by security researcher Dhiraj Mishra.

Technical details

The vulnerability is categorized as CWE-427 (Uncontrolled Search Path Element) with a CVSS v3.1 Base Score of 7.8 (High). The attack requires local access and user interaction, with the prerequisite that the victim must be tricked into placing a malicious DLL in the same directory where the installer is started from. The CVSS vector string is CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (Bosch PSIRT).

Impact

If successfully exploited, the vulnerability could allow an attacker to execute arbitrary code on the victim's system with the same privileges as the user running the installer. This could potentially lead to complete compromise of the affected system's confidentiality, integrity, and availability (Bosch PSIRT).

Mitigation and workarounds

For mitigation, users are advised not to execute installers from directories that are accessible by other users or directories where potentially malicious DLLs could be located (e.g., the default Downloads directory). It is recommended to move executables to new separated directories not accessible by other users and only start the executables from there. Additionally, users should not execute installers directly from the default Downloads directory and should not accept unsolicited download prompts in a browser (Bosch PSIRT).

Additional resources


SourceThis report was generated using AI

Related Bosch Monitor Wall vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-6789HIGH7.8
  • Bosch Monitor WallBosch Monitor Wall
  • cpe:2.3:a:bosch:monitor_wall
NoNoMar 25, 2021
CVE-2023-32230HIGH7.5
  • Bosch Video Recording Manager (VRM)Bosch Video Recording Manager (VRM)
  • cpe:2.3:a:bosch:video_recording_manager
NoNoDec 18, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management