Deserialization of Untrusted Data in Bosch BVMS Mobile Video Service
CVE-2020-6770
10CRITICAL
Key Information:
- Vendor
Bosch
- Vendor
- CVE Published:
- 29 January 2020
What is CVE-2020-6770?
Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on the system. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.0.329 and 7.5 and older. This affects Bosch DIVAR IP 3000 and DIVAR IP 7000 if a vulnerable BVMS version is installed.
Affected Version(s)
BVMS Mobile Video Service <= 8.0.0.329
BVMS Mobile Video Service <= 9.0.0.827
BVMS Mobile Video Service <= 10.0.0.1225