CVE-2020-6785
Uncontrolled Search Path Element in Bosch BVMS and BVMS Viewer
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 7.8EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
25 mar 2021Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Loading a DLL through an Uncontrolled Search Path Element in Bosch BVMS and BVMS Viewer in versions 10.1.0, 10.0.1, 10.0.0 and 9.0.0 and older potentially allows an attacker to execute arbitrary code on a victim's system. This affects both the installer as well as the installed application. This also affects Bosch DIVAR IP 7000 R2, Bosch DIVAR IP all-in-one 5000 and Bosch DIVAR IP all-in-one 7000 with installers and installed BVMS versions prior to BVMS 10.1.1.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Produtos afetados
Bosch · BVMSBosch · BVMS ViewerBosch · DIVAR IP 7000 R2Bosch · DIVAR IP all-in-one 5000Bosch · DIVAR IP all-in-one 7000Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →