CVE-2020-6769

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
07/02/2020
Last modified:
12/02/2020

Description

Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote attacker to retrieve and set arbitrary configuration data of the Video Streaming Gateway. A successful attack can impact the confidentiality and availability of live and recorded video data of all cameras configured to be controlled by the VSG as well as the recording storage associated with the VSG. This affects Bosch Video Streaming Gateway versions 6.45

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bosch:video_streaming_gateway:*:*:*:*:*:*:*:* 6.42.10 (including)
cpe:2.3:a:bosch:video_streaming_gateway:*:*:*:*:*:*:*:* 6.43 (including) 6.43.0023 (including)
cpe:2.3:a:bosch:video_streaming_gateway:*:*:*:*:*:*:*:* 6.44 (including) 6.44.022 (including)
cpe:2.3:a:bosch:video_streaming_gateway:*:*:*:*:*:*:*:* 6.45 (including) 6.45.08 (including)
cpe:2.3:o:bosch:divar_ip_2000_firmware:*:*:*:*:*:*:*:* 3.62.0019 (including)
cpe:2.3:h:bosch:divar_ip_2000:-:*:*:*:*:*:*:*
cpe:2.3:o:bosch:divar_ip_5000_firmware:*:*:*:*:*:*:*:* 3.80.0039 (including)
cpe:2.3:h:bosch:divar_ip_5000:-:*:*:*:*:*:*:*
cpe:2.3:a:bosch:video_streaming_gateway:*:*:*:*:*:*:*:* 6.42.10 (including)
cpe:2.3:a:bosch:video_streaming_gateway:*:*:*:*:*:*:*:* 6.43 (including) 6.43.0023 (including)
cpe:2.3:a:bosch:video_streaming_gateway:*:*:*:*:*:*:*:* 6.44 (including) 6.44.022 (including)
cpe:2.3:a:bosch:video_streaming_gateway:*:*:*:*:*:*:*:* 6.45 (including) 6.45.08 (including)
cpe:2.3:h:bosch:divar_ip_3000:-:*:*:*:*:*:*:*
cpe:2.3:a:bosch:video_streaming_gateway:*:*:*:*:*:*:*:* 6.42.10 (including)
cpe:2.3:a:bosch:video_streaming_gateway:*:*:*:*:*:*:*:* 6.43 (including) 6.43.0023 (including)


References to Advisories, Solutions, and Tools