Improper Authorization in Bosch VMS Software
CVE-2023-28175

7.1HIGH

Key Information:

Vendor

Bosch

Vendor
CVE Published:
15 June 2023

What is CVE-2023-28175?

An improper authorization vulnerability exists in the SSH server component of Bosch VMS versions 11.0, 11.1.0, and 11.1.1. This flaw allows a remote authenticated user to perform unauthorized access to specific resources within the trusted internal network by exploiting port forwarding requests. Such access could potentially lead to further security breaches if exploited.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Bosch DIVAR IP 3000 7.5 <= 8.0

Bosch DIVAR IP 7000 R1 7.5 <= 8.0

Bosch DIVAR IP 7000 R2 7.5 <= 11.1.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.