Записи Bosch
109 опубликованных записей вендора bosch.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 15
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
- CWE-284 Improper Access Control9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')9
- CWE-427 Uncontrolled Search Path Element7
- CWE-121 Stack-based Buffer Overflow6
- CWE-502 Deserialization of Untrusted Data5
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
109 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2020-6779Эксплойта нет | Hard-coded Credentials in the Database of Bosch FSM-2500 Server and Bosch FSM-5000 Serverbosch · fsm-2500 firmware · CWE-798 | Критическая10,0 | — | 3,7 % | 26 янв. 2021 г. |
40В плане | CVE-2020-6770Эксплойта нет | Deserialization of Untrusted Data in Bosch BVMS Mobile Video Servicebosch · bosch video management system mobile video service · CWE-502 | Критическая9,8 | — | 3,6 % | 7 февр. 2020 г. |
40В плане | CVE-2018-19036Эксплойта нет | An issue was discovered in several Bosch IP cameras for firmware versions 6.32 and higher.bosch · common product platform 4 firmware · CWE-119 | Критическая9,8 | — | 2,4 % | 17 дек. 2018 г. |
40В плане | CVE-2022-32534Эксплойта нет | OS Command Injectionbosch · pra-es8p2s firmware · CWE-20 | Критическая9,8 | — | 2,4 % | 23 июн. 2022 г. |
40В плане | CVE-2019-6957Эксплойта нет | Buffer Overflow for Bosch Video Systems, PSIM and Access Control Systemsbosch · access professional edition · CWE-787 | Критическая9,8 | — | 2,0 % | 29 мая 2019 г. |
40В плане | CVE-2018-20299Эксплойта нет | An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firmware before 6.52.4.bosch · 360-indoor camera firmware · CWE-119 | Критическая9,8 | — | 1,9 % | 19 дек. 2018 г. |
39Наблюдать | CVE-2021-23857Эксплойта нет | Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the passworbosch · rexroth indramotion mlc l20 firmware · CWE-836 | Критическая9,8 | — | 1,2 % | 4 окт. 2021 г. |
39Наблюдать | CVE-2019-11898Эксплойта нет | Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools.bosch · access · CWE-798 | Критическая9,9 | — | 1,1 % | 12 сент. 2019 г. |
39Наблюдать | CVE-2019-11684Эксплойта нет | Improper Access Control in Bosch Video Recording Managerbosch · video recording manager · CWE-306 | Критическая9,8 | — | 1,0 % | 26 февр. 2021 г. |
39Наблюдать | CVE-2021-23853Эксплойта нет | Improper Input Validation of HTTP Headersbosch · cpp4 firmware · CWE-20 | Критическая9,8 | — | 0,9 % | 9 июн. 2021 г. |
39Наблюдать | CVE-2022-32535Эксплойта нет | Web server runs as rootbosch · pra-es8p2s firmware · CWE-250 | Критическая9,8 | — | 0,8 % | 23 июн. 2022 г. |
39Наблюдать | CVE-2023-48266Эксплойта нет | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Exebosch · nexo-os · CWE-121 | Критическая9,8 | — | 0,8 % | 10 янв. 2024 г. |
39Наблюдать | CVE-2023-48264Эксплойта нет | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Exebosch · nexo-os · CWE-121 | Критическая9,8 | — | 0,8 % | 10 янв. 2024 г. |
39Наблюдать | CVE-2023-48265Эксплойта нет | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Exebosch · nexo-os · CWE-121 | Критическая9,8 | — | 0,8 % | 10 янв. 2024 г. |
39Наблюдать | CVE-2023-48263Эксплойта нет | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Exebosch · nexo-os · CWE-122 | Критическая9,8 | — | 0,8 % | 10 янв. 2024 г. |
39Наблюдать | CVE-2023-48262Эксплойта нет | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Exebosch · nexo-os · CWE-121 | Критическая9,8 | — | 0,8 % | 10 янв. 2024 г. |
39Наблюдать | CVE-2023-48245Эксплойта нет | The vulnerability allows an unauthenticated remote attacker to upload arbitrary files under the context of the application OS user (“root”) bosch · nexo-os · CWE-862 | Критическая9,8 | — | 0,6 % | 10 янв. 2024 г. |
39Наблюдать | CVE-2023-48250Эксплойта нет | The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded acbosch · nexo-os · CWE-798 | Критическая9,8 | — | 0,6 % | 10 янв. 2024 г. |
39Наблюдать | CVE-2023-48251Эксплойта нет | The vulnerability allows a remote attacker to authenticate to the SSH service with root privileges through a hidden hard-coded account.bosch · nexo-os · CWE-798 | Критическая9,8 | — | 0,6 % | 10 янв. 2024 г. |
37Наблюдать | CVE-2020-6769Эксплойта нет | Missing Authentication for Critical Function in Bosch Video Streaming Gatewaybosch · video streaming gateway · CWE-306 | Критическая9,1 | — | 2,2 % | 7 февр. 2020 г. |
36Наблюдать | CVE-2019-6958Эксплойта нет | Improper Access Control for Bosch Video Systems, PSIM and Access Control Systemsbosch · access professional edition · CWE-306 | Критическая9,1 | — | 1,5 % | 29 мая 2019 г. |
36Наблюдать | CVE-2021-23847Эксплойта нет | Unauthenticated Information Extraction Vulnerabilitybosch · cpp6 firmware · CWE-287 | Критическая9,1 | — | 1,4 % | 9 июн. 2021 г. |
35Наблюдать | CVE-2019-11897Эксплойта нет | Server-side request forgery in the backup & restore functionality of ProSyst mBS SDK and Bosch IoT Gateway Softwarebosch · iot gateway software · CWE-918 | Высокая8,6 | — | 1,8 % | 21 авг. 2019 г. |
35Наблюдать | CVE-2024-25002Эксплойта нет | Command Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access to the device.bosch · network synchronizer enterprise · CWE-78 | Высокая8,8 | — | 1,2 % | 25 мар. 2024 г. |
35Наблюдать | CVE-2023-48243Эксплойта нет | The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS userbosch · nexo-os · CWE-22 | Высокая8,8 | — | 1,1 % | 10 янв. 2024 г. |
- CVE-2020-677941В плане
Hard-coded Credentials in the Database of Bosch FSM-2500 Server and Bosch FSM-5000 Server
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %bosch · fsm-2500 firmware26 янв. 2021 г.
- CVE-2020-677040В плане
Deserialization of Untrusted Data in Bosch BVMS Mobile Video Service
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %bosch · bosch video management system mobile video service7 февр. 2020 г.
- CVE-2018-1903640В плане
An issue was discovered in several Bosch IP cameras for firmware versions 6.32 and higher.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %bosch · common product platform 4 firmware17 дек. 2018 г.
- CVE-2022-3253440В плане
OS Command Injection
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %bosch · pra-es8p2s firmware23 июн. 2022 г.
- CVE-2019-695740В плане
Buffer Overflow for Bosch Video Systems, PSIM and Access Control Systems
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %bosch · access professional edition29 мая 2019 г.
- CVE-2018-2029940В плане
An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firmware before 6.52.4.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %bosch · 360-indoor camera firmware19 дек. 2018 г.
- CVE-2021-2385739Наблюдать
Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the passwor
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bosch · rexroth indramotion mlc l20 firmware4 окт. 2021 г.
- CVE-2019-1189839Наблюдать
Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools.
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %bosch · access12 сент. 2019 г.
- CVE-2019-1168439Наблюдать
Improper Access Control in Bosch Video Recording Manager
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bosch · video recording manager26 февр. 2021 г.
- CVE-2021-2385339Наблюдать
Improper Input Validation of HTTP Headers
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bosch · cpp4 firmware9 июн. 2021 г.
- CVE-2022-3253539Наблюдать
Web server runs as root
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bosch · pra-es8p2s firmware23 июн. 2022 г.
- CVE-2023-4826639Наблюдать
The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Exe
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bosch · nexo-os10 янв. 2024 г.
- CVE-2023-4826439Наблюдать
The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Exe
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bosch · nexo-os10 янв. 2024 г.
- CVE-2023-4826539Наблюдать
The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Exe
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bosch · nexo-os10 янв. 2024 г.
- CVE-2023-4826339Наблюдать
The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Exe
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bosch · nexo-os10 янв. 2024 г.
- CVE-2023-4826239Наблюдать
The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Exe
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bosch · nexo-os10 янв. 2024 г.
- CVE-2023-4824539Наблюдать
The vulnerability allows an unauthenticated remote attacker to upload arbitrary files under the context of the application OS user (“root”)
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bosch · nexo-os10 янв. 2024 г.
- CVE-2023-4825039Наблюдать
The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded ac
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bosch · nexo-os10 янв. 2024 г.
- CVE-2023-4825139Наблюдать
The vulnerability allows a remote attacker to authenticate to the SSH service with root privileges through a hidden hard-coded account.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bosch · nexo-os10 янв. 2024 г.
- CVE-2020-676937Наблюдать
Missing Authentication for Critical Function in Bosch Video Streaming Gateway
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %bosch · video streaming gateway7 февр. 2020 г.
- CVE-2019-695836Наблюдать
Improper Access Control for Bosch Video Systems, PSIM and Access Control Systems
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %bosch · access professional edition29 мая 2019 г.
- CVE-2021-2384736Наблюдать
Unauthenticated Information Extraction Vulnerability
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %bosch · cpp6 firmware9 июн. 2021 г.
- CVE-2019-1189735Наблюдать
Server-side request forgery in the backup & restore functionality of ProSyst mBS SDK and Bosch IoT Gateway Software
ВысокаяCVSS 8,6Эксплойта нетEPSS 2 %bosch · iot gateway software21 авг. 2019 г.
- CVE-2024-2500235Наблюдать
Command Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access to the device.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bosch · network synchronizer enterprise25 мар. 2024 г.
- CVE-2023-4824335Наблюдать
The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bosch · nexo-os10 янв. 2024 г.