CVE-2020-6769
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
07/02/2020
Last modified:
12/02/2020
Description
Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote attacker to retrieve and set arbitrary configuration data of the Video Streaming Gateway. A successful attack can impact the confidentiality and availability of live and recorded video data of all cameras configured to be controlled by the VSG as well as the recording storage associated with the VSG. This affects Bosch Video Streaming Gateway versions 6.45
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Base Score 2.0
6.40
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:bosch:video_streaming_gateway:*:*:*:*:*:*:*:* | 6.42.10 (including) | |
| cpe:2.3:a:bosch:video_streaming_gateway:*:*:*:*:*:*:*:* | 6.43 (including) | 6.43.0023 (including) |
| cpe:2.3:a:bosch:video_streaming_gateway:*:*:*:*:*:*:*:* | 6.44 (including) | 6.44.022 (including) |
| cpe:2.3:a:bosch:video_streaming_gateway:*:*:*:*:*:*:*:* | 6.45 (including) | 6.45.08 (including) |
| cpe:2.3:o:bosch:divar_ip_2000_firmware:*:*:*:*:*:*:*:* | 3.62.0019 (including) | |
| cpe:2.3:h:bosch:divar_ip_2000:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:bosch:divar_ip_5000_firmware:*:*:*:*:*:*:*:* | 3.80.0039 (including) | |
| cpe:2.3:h:bosch:divar_ip_5000:-:*:*:*:*:*:*:* | ||
| cpe:2.3:a:bosch:video_streaming_gateway:*:*:*:*:*:*:*:* | 6.42.10 (including) | |
| cpe:2.3:a:bosch:video_streaming_gateway:*:*:*:*:*:*:*:* | 6.43 (including) | 6.43.0023 (including) |
| cpe:2.3:a:bosch:video_streaming_gateway:*:*:*:*:*:*:*:* | 6.44 (including) | 6.44.022 (including) |
| cpe:2.3:a:bosch:video_streaming_gateway:*:*:*:*:*:*:*:* | 6.45 (including) | 6.45.08 (including) |
| cpe:2.3:h:bosch:divar_ip_3000:-:*:*:*:*:*:*:* | ||
| cpe:2.3:a:bosch:video_streaming_gateway:*:*:*:*:*:*:*:* | 6.42.10 (including) | |
| cpe:2.3:a:bosch:video_streaming_gateway:*:*:*:*:*:*:*:* | 6.43 (including) | 6.43.0023 (including) |
To consult the complete list of CPE names with products and versions, see this page



