CVE-2022-32540
Last modified
CVE-2022-32540 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Information Disclosure in Operator Client application in BVMS 10.1.1, 11.0 and 11.1.0 and VIDEOJET Decoder VJD-7513 versions 10.23 and 10.30 allows man-in-the-middle attacker to compromise confidential video stream. This is only applicable for UDP encryption when target system contains cameras with platform CPP13 or CPP14 and firmware version 8.x.. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
Information Disclosure in Operator Client application in BVMS 10.1.1, 11.0 and 11.1.0 and VIDEOJET Decoder VJD-7513 versions 10.23 and 10.30 allows man-in-the-middle attacker to compromise confidential video stream. This is only applicable for UDP encryption when target system contains cameras with platform CPP13 or CPP14 and firmware version 8.x.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bosch | Bosch Video Management System | >= 10.1, <= 10.1.1 |
| Bosch | Bosch Video Management System | >= 11.1, <= 11.1.0 |
| Bosch | Bosch Video Management System | 11.0 |
| Bosch | Videojet Decoder 7513 Firmware | 10.23.0002 |
| Bosch | Videojet Decoder 7513 Firmware | 10.30.0005 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-32540?
How severe is CVE-2022-32540?
How do I fix CVE-2022-32540?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-32533Apache Jetspeed-2 does not sufficiently filter untrusted use…9.8
- CVE-2022-32534The Bosch Ethernet switch PRA-ES8P2S with software version 1…9.8
- CVE-2022-32535The Bosch Ethernet switch PRA-ES8P2S with software version 1…9.8
- CVE-2022-32536The user access rights validation in the web server of the B…8.8
- CVE-2022-32537A vulnerability exists which could allow an unauthorized use…4.8
- CVE-2022-3254The WordPress Classifieds Plugin WordPress plugin before 4.3…9.8
- CVE-2022-32543An integer overflow vulnerability exists in the way ESTsoft …7.8
- CVE-2022-32544Operation restriction bypass vulnerability in Project of Cyb…4.3
- CVE-2022-32545A vulnerability was found in ImageMagick, causing an outside…7.8
- CVE-2022-32546A vulnerability was found in ImageMagick, causing an outside…7.8
- CVE-2022-32547In ImageMagick, there is load of misaligned address for type…7.8
- CVE-2022-32548An issue was discovered on certain DrayTek Vigor routers bef…9.8
Are you affected by CVE-2022-32540?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
