10
CVE-2020-6770
- EPSS 11.3%
- Veröffentlicht 07.02.2020 21:15:10
- Zuletzt bearbeitet 21.11.2024 05:36:09
- Quelle psirt@bosch.com
- CVE-Watchlists
- Unerledigt
Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on the system. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.0.329 and 7.5 and older. This affects Bosch DIVAR IP 3000 and DIVAR IP 7000 if a vulnerable BVMS version is installed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bosch ≫ Bosch Video Management System Mobile Video Service Version <= 7.5
Bosch ≫ Bosch Video Management System Mobile Video Service Version >= 8.0 <= 8.0.0.329
Bosch ≫ Bosch Video Management System Mobile Video Service Version >= 9.0 <= 9.0.0.827
Bosch ≫ Bosch Video Management System Mobile Video Service Version >= 10.0 <= 10.0.0.1225
Bosch ≫ Divar Ip 3000 Firmware Version-
Bosch ≫ Divar Ip 7000 Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 11.3% | 0.932 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
| psirt@bosch.com | 10 | 3.9 | 6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.