Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
bosch access professional edition vulnerabilities and exploits
(subscribe to this query)
409
VMScore
CVE-2021-23843
The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a password protection on configured devices to restrict access to the configuration of an AMC2. An attacker can circumvent this protect...
Bosch Amc2 Firmware -
Bosch Access Management System 3.0
Bosch Access Professional Edition
Bosch Building Integration System
320
VMScore
CVE-2021-23842
Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An attacker could retrieve the key from the firmware to decrypt network traffic between the AMC2 and the host system. Thus, an attacker can exploit this vulnerabili...
Bosch Amc2 Firmware -
Bosch Access Management System 3.0
Bosch Access Professional Edition
Bosch Building Integration System
445
VMScore
CVE-2021-23859
An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM installation this crash also opens the possibility to send further unauthenticated commands to the service. On some products the interf...
Bosch Bosch Video Management System
Bosch Bosch Video Management System 10.1
Bosch Bosch Video Management System 11.0
Bosch Video Recording Manager
Bosch Access Easy Controller Firmware
Bosch Access Professional Edition
Bosch Building Integration System
Bosch Video Recording Manager Exporter
570
VMScore
CVE-2019-6958
A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Configuration Manager, Building Integration System (BIS) with Video Engine, Access Professional Edition (APE), Access Easy Con...
Bosch Bosch Video Management System
Bosch Access Professional Edition
Bosch Building Integration System
Bosch Building Integration System 4.5
Bosch Building Integration System 4.6
Bosch Building Integration System 4.6.1
Bosch Bosch Video Client
Bosch Video Sdk
Bosch Configuration Manager
Bosch Dip 2000 Firmware
Bosch Dip 3000 Firmware -
Bosch Dip 5000 Firmware
Bosch Dip 7000 Firmware -
Bosch Access Easy Controller Firmware 2.1.8.5
Bosch Access Easy Controller Firmware 2.1.9.0
Bosch Access Easy Controller Firmware 2.1.9.1
Bosch Access Easy Controller Firmware 2.1.9.3
668
VMScore
CVE-2019-6957
A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Video Recording Manager (VRM), Video Streaming Gateway (VSG), Configuration Manager, Building Integration System (BIS) with Vi...
Bosch Video Recording Manager
Bosch Bosch Video Management System
Bosch Access Professional Edition
Bosch Building Integration System
Bosch Building Integration System 4.5
Bosch Building Integration System 4.6
Bosch Building Integration System 4.6.1
Bosch Bosch Video Client
Bosch Video Sdk
Bosch Configuration Manager
Bosch Video Streaming Gateway
Bosch Dip 2000 Firmware
Bosch Dip 3000 Firmware -
Bosch Dip 5000 Firmware
Bosch Dip 7000 Firmware -
Bosch Access Easy Controller Firmware 2.1.8.5
Bosch Access Easy Controller Firmware 2.1.9.3
Bosch Access Easy Controller Firmware 2.1.9.1
Bosch Access Easy Controller Firmware 2.1.9.0
578
VMScore
CVE-2019-11898
Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The service tool is discontinued with Bosch Access Professional Edition (APE) 3.8.
Bosch Access
356
VMScore
CVE-2019-11899
An unauthenticated attacker can achieve unauthorized access to sensitive data by exploiting Windows SMB protocol on a client installation. With Bosch Access Professional Edition (APE) 3.8, client installations need to be authorized by the APE administrator.
Bosch Access
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48700
CVE-2022-48689
CVE-2024-27956
CVE-2023-6363
SQL
NULL pointer dereference
CVE-2023-41830
CVE-2015-2051
arbitrary
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started