Uncontrolled Search Path Element in Bosch Video Streaming Gateway Installer
CVE-2020-6790

7.8HIGH

Key Information:

Vendor

Bosch

Vendor
CVE Published:
24 March 2021

What is CVE-2020-6790?

Calling an executable through an Uncontrolled Search Path Element in the Bosch Video Streaming Gateway installer up to and including version 6.45.10 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious exe in the same directory where the installer is started from.

Affected Version(s)

Video Streaming Gateway <= 6.45.10

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dhiraj Mishra
.