CVE-2019-6958

CRITICALCVSS 9.1/10EPSS 1.52%

Last modified

CVE-2019-6958 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Configuration Manager, Building Integration System (BIS) with Video Engine, Access Professional Edition (APE), Access Easy Controller (AEC), Bosch Video Client (BVC) and Video SDK (VSDK). The RCP+ network port allows access without authentication. EPSS estimates a 1.52% chance of exploitation in the next 30 days.

Description

A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Configuration Manager, Building Integration System (BIS) with Video Engine, Access Professional Edition (APE), Access Easy Controller (AEC), Bosch Video Client (BVC) and Video SDK (VSDK). The RCP+ network port allows access without authentication. Adding authentication feature to the respective library fixes the issue. The issue is classified as "CWE-284: Improper Access Control." This vulnerability, for example, allows a potential attacker to delete video or read video data.

Metrics

CVSS 3.1
9.1/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS Probability
1.52%

71.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
BoschAccess Professional Edition>= 3.0, <= 3.7
BoschBosch Video Client< 1.7.6.079
BoschBosch Video Management System<= 9.0
BoschBuilding Integration System>= 2.2, <= 4.4
BoschBuilding Integration System4.5
BoschBuilding Integration System4.6
BoschBuilding Integration System4.6.1
BoschConfiguration Manager< 6.10
BoschVideo Sdk< 6.32.0099
BoschDip 2000 Firmware< 0380.037
BoschDip 3000 FirmwareAll versions
BoschDip 5000 Firmware< 038.037
BoschDip 7000 FirmwareAll versions
BoschAccess Easy Controller Firmware2.1.8.5
BoschAccess Easy Controller Firmware2.1.9.0
BoschAccess Easy Controller Firmware2.1.9.1
BoschAccess Easy Controller Firmware2.1.9.3

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-6958?
A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Configuration Manager, Building Integration System (BIS) with Video Engine, Access Professional Edition (APE), Access Easy Controller (AEC), Bosch Video Client (BVC) and Video SDK (VSDK). The RCP+ network port allows access without authentication. Adding authentication feature to the respective library fixes the issue. The issue is classified as "CWE-284: Improper Access Control." This vulnerability, for example, allows a potential attacker to delete video or read video data.
How severe is CVE-2019-6958?
CVE-2019-6958 has a CVSS score of 9.1/10 (CRITICAL severity). The EPSS model estimates a 1.52% probability of exploitation in the next 30 days.
How do I fix CVE-2019-6958?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-6958?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST