CVE-2019-11684
Improper Access Control in Bosch Video Recording Manager
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Access Control in the RCP+ server of the Bosch Video Recording Manager (VRM) component allows arbitrary and unauthenticated access to a limited subset of certificates, stored in the underlying Microsoft Windows operating system. The fixed versions implement modified authentication checks. Prior releases of VRM software version 3.70 are considered unaffected. This vulnerability affects VRM v3.70.x, v3.71 < v3.71.0034 and v3.81 < 3.81.0050; DIVAR IP 5000 3.80 < 3.80.0039; BVMS all versions using VRM.
Un control de acceso inapropiado en el servidor RCP+ del componente Bosch Video Recording Manager (VRM), permite el acceso arbitrario y no autenticado a un subconjunto limitado de certificados, almacenados en el sistema operativo subyacente de Microsoft Windows. Las versiones corregidas implementan comprobaciones de autenticación modificadas. Las versiones anteriores a 3.70 del software VRM no son consideradas afectadas. Esta vulnerabilidad afecta a VRM versiones v3.70.x, v3.71 anteriores a v3.71.0034 y versiones v3.81 anteriores a 3.81.0050; DIVAR IP 5000 versiones 3.80 anteriores a 3.80.0039; BVMS todas las versiones que usan VRM
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-05-02 CVE Reserved
- 2021-02-26 CVE Published
- 2023-11-12 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://psirt.bosch.com/security-advisories/bosch-sa-804652.html | 2021-07-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bosch Search vendor "Bosch" | Divar Ip 5000 Firmware Search vendor "Bosch" for product "Divar Ip 5000 Firmware" | >= 3.80 < 3.80.0039 Search vendor "Bosch" for product "Divar Ip 5000 Firmware" and version " >= 3.80 < 3.80.0039" | - |
Affected
| in | Bosch Search vendor "Bosch" | Divar Ip 5000 Search vendor "Bosch" for product "Divar Ip 5000" | - | - |
Safe
|
Bosch Search vendor "Bosch" | Video Recording Manager Search vendor "Bosch" for product "Video Recording Manager" | >= 3.70 < 3.71.0034 Search vendor "Bosch" for product "Video Recording Manager" and version " >= 3.70 < 3.71.0034" | - |
Affected
| ||||||
Bosch Search vendor "Bosch" | Video Recording Manager Search vendor "Bosch" for product "Video Recording Manager" | >= 3.81 < 3.81.0050 Search vendor "Bosch" for product "Video Recording Manager" and version " >= 3.81 < 3.81.0050" | - |
Affected
| ||||||
Bosch Search vendor "Bosch" | Video Management System Search vendor "Bosch" for product "Video Management System" | 3.70.0056 Search vendor "Bosch" for product "Video Management System" and version "3.70.0056" | - |
Affected
| ||||||
Bosch Search vendor "Bosch" | Video Management System Search vendor "Bosch" for product "Video Management System" | 3.70.0058 Search vendor "Bosch" for product "Video Management System" and version "3.70.0058" | - |
Affected
| ||||||
Bosch Search vendor "Bosch" | Video Management System Search vendor "Bosch" for product "Video Management System" | 3.70.0060 Search vendor "Bosch" for product "Video Management System" and version "3.70.0060" | - |
Affected
| ||||||
Bosch Search vendor "Bosch" | Video Management System Search vendor "Bosch" for product "Video Management System" | 3.70.0062 Search vendor "Bosch" for product "Video Management System" and version "3.70.0062" | - |
Affected
| ||||||
Bosch Search vendor "Bosch" | Video Management System Search vendor "Bosch" for product "Video Management System" | 3.71.0022 Search vendor "Bosch" for product "Video Management System" and version "3.71.0022" | - |
Affected
| ||||||
Bosch Search vendor "Bosch" | Video Management System Search vendor "Bosch" for product "Video Management System" | 3.71.0029 Search vendor "Bosch" for product "Video Management System" and version "3.71.0029" | - |
Affected
| ||||||
Bosch Search vendor "Bosch" | Video Management System Search vendor "Bosch" for product "Video Management System" | 3.71.0031 Search vendor "Bosch" for product "Video Management System" and version "3.71.0031" | - |
Affected
| ||||||
Bosch Search vendor "Bosch" | Video Management System Search vendor "Bosch" for product "Video Management System" | 3.71.0032 Search vendor "Bosch" for product "Video Management System" and version "3.71.0032" | - |
Affected
| ||||||
Bosch Search vendor "Bosch" | Video Management System Search vendor "Bosch" for product "Video Management System" | 3.81.0032 Search vendor "Bosch" for product "Video Management System" and version "3.81.0032" | - |
Affected
| ||||||
Bosch Search vendor "Bosch" | Video Management System Search vendor "Bosch" for product "Video Management System" | 3.81.0038 Search vendor "Bosch" for product "Video Management System" and version "3.81.0038" | - |
Affected
| ||||||
Bosch Search vendor "Bosch" | Video Management System Search vendor "Bosch" for product "Video Management System" | 3.81.0048 Search vendor "Bosch" for product "Video Management System" and version "3.81.0048" | - |
Affected
|