Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

138 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.5%—Bosch Cpp13 FirmwareBosch Cpp14 Firmware18/12/202317/6/2026
A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administrative rights to run arbitrary commands on the OS of the camera.
ModificadaMedia (5.9)0.56%—Bosch Building Integration System Video EngineBosch Video Management SystemBosch Video Management System ViewerBosch Configuration Manager+1018/12/202317/6/2026
An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.
ModificadaAlta (7.5)0.73%—Bosch Monitor WallBosch Videojet Decoder 7513 FirmwareBosch Videojet Decoder 7523 FirmwareBosch Video Recording Manager+118/12/202317/6/2026
An improper handling of a malformed API request to an API server in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation.
ModificadaMedia (5.3)0.60%—Bosch Cpp14 FirmwareBosch Cpp13 FirmwareBosch Cpp7.3 FirmwareBosch Cpp7 Firmware+218/12/202317/6/2026
An information disclosure vulnerability was discovered in Bosch IP camera devices allowing an unauthenticated attacker to retrieve information (like capabilities) about the device itself and network settings of the device, disclosing possibly internal network settings if the device is connected to the internet.
ModificadaAlta (8.8)0.43%—Boschrexroth Ctrlx HMI WEB Panel Wr2107 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2110 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2115 Firmware25/10/202317/6/2026
The Android Client application, when enrolled to the AppHub server, connects to an MQTT broker to exchange messages and receive commands to execute on the HMI device. The protocol builds on top of MQTT to implement the remote management of the device is encrypted with a hard-coded DES symmetric key, that can be…
ModificadaAlta (8.8)0.45%—Boschrexroth Ctrlx HMI WEB Panel Wr2107 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2110 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2115 Firmware25/10/202317/6/2026
The Android Client application, when enrolled to the AppHub server,connects to an MQTT broker without enforcing any server authentication. This issue allows an attacker to force the Android Client application to connect to a malicious MQTT broker, enabling it to send fake messages to the HMI device
ModificadaMedia (6.8)0.34%—Boschrexroth Ctrlx HMI WEB Panel Wr2107 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2110 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2115 Firmware25/10/202317/6/2026
The vulnerability allows a low privileged user that have access to the device when locked in Kiosk mode to install an arbitrary Android application and leverage it to have access to critical device settings such as the device power management or eventually the device secure settings (ADB debug).
ModificadaAlta (8.8)0.12%—Boschrexroth Ctrlx HMI WEB Panel Wr2107 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2110 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2115 Firmware25/10/202317/6/2026
The Android Client application, when enrolled with the define method 1 (the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip address and credentials to connect to a remote MQTT broker entity) instead of HTTPS and this feature is not configurable by the user. Due to…
ModificadaAlta (8.8)0.39%—Boschrexroth Ctrlx HMI WEB Panel Wr2107 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2110 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2115 Firmware25/10/202317/6/2026
The Android Client application, when enrolled with the define method 1(the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip address and credentials to connect to a remote MQTT broker entity) instead of HTTPS and this feature is not configurable by the user.
ModificadaAlta (7.8)0.19%—Boschrexroth Ctrlx HMI WEB Panel Wr2107 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2110 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2115 Firmware25/10/202317/6/2026
The vulnerability allows a low privileged (untrusted) application to modify a critical system property that should be denied, in order to enable the ADB (Android Debug Bridge) protocol to be exposed on the network, exploiting it to gain a privileged shell on the device without requiring the physical access through USB.
ModificadaBaja (3.3)0.18%—Boschrexroth Ctrlx HMI WEB Panel Wr2107 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2110 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2115 Firmware25/10/202317/6/2026
The vulnerability allows an unprivileged(untrusted) third-party application to interact with a content-provider unsafely exposed by the Android Agent application, potentially modifying sensitive settings of the Android Client application itself.
ModificadaAlta (7.8)0.20%—Boschrexroth Ctrlx HMI WEB Panel Wr2107 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2110 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2115 Firmware25/10/202317/6/2026
The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client application, inducing it to connect to an attacker - controlled malicious server.This is possible by forging a valid broadcast intent encrypted with a hardcoded RSA key pair
ModificadaAlta (8.8)0.42%—Boschrexroth Ctrlx HMI WEB Panel Wr2107 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2110 FirmwareBoschrexroth Ctrlx HMI WEB Panel Wr2115 Firmware25/10/202317/6/2026
The vulnerability allows an unprivileged user with access to the subnet of the TPC-110W device to gain a root shell on the device itself abusing the lack of authentication of the ‘su’ binary file installed on the device that can be accessed through the ADB (Android Debug Bridge) protocol exposed on the network.
ModificadaAlta (7.2)1.2%—Bosch RTS Vlink Virtual Matrix18/9/202317/6/2026
A command injection vulnerability exists in RTS VLink Virtual Matrix Software Versions v5 (< 5.7.6) and v6 (< 6.5.0) that allows an attacker to perform arbitrary code execution via the admin web interface.
ModificadaAlta (7.1)0.36%—Bosch Building Integration System30/6/202317/6/2026
Improper Information in Cybersecurity Guidebook in Bosch Building Integration System (BIS) 5.0 may lead to wrong configuration which allows local users to access data via network
ModificadaMedia (6.5)0.60%—Bosch Cpp13 FirmwareBosch Cpp14 Firmware15/6/202317/6/2026
Due to an error in the software interface to the secure element chip on Bosch IP cameras of family CPP13 and CPP14, the chip can be permanently damaged when enabling the Stream security option (signing of the video stream) with option MD5, SHA-1 or SHA-256.
ModificadaAlta (7.7)0.46%—Bosch Video Management SystemBosch Video Management System ViewerBosch Divar IP 3000 FirmwareBosch Divar IP 6000 Firmware+515/6/202317/6/2026
Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access resources within the trusted internal network via a port forwarding request.
ModificadaAlta (8.8)0.43%—Bosch B420 Firmware8/2/202317/6/2026
An Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring any sort of authorization or authentication due to the IP based authorization. If an authorized user has accessed a publicly available B420 product using valid credentials, an insider attacker can gain…
ModificadaMedia (4.8)0.33%—Bosch Videojet Multi 4000 Firmware27/10/202217/6/2026
Incomplete filtering of JavaScript code in different configuration fields of the web based interface of the VIDEOJET multi 4000 allows an attacker with administrative credentials to store JavaScript code which will be executed for all administrators accessing the same configuration option.
ModificadaMedia (4.7)0.34%—Bosch Videojet Multi 4000 Firmware27/10/202217/6/2026
An error in the URL handler of the VIDEOJET multi 4000 may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the encoder address can send a crafted link to a user, which will execute JavaScript code in the context of the user.
ModificadaMedia (5.9)0.36%—Bosch Video Management SystemBosch Videojet Decoder 7513 Firmware30/9/202217/6/2026
Information Disclosure in Operator Client application in BVMS 10.1.1, 11.0 and 11.1.0 and VIDEOJET Decoder VJD-7513 versions 10.23 and 10.30 allows man-in-the-middle attacker to compromise confidential video stream. This is only applicable for UDP encryption when target system contains cameras with platform CPP13 or…
ModificadaMedia (5.4)0.60%—Bosch Bf-os1/8/202217/6/2026
File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access different resources, which may contain sensitive information.
ModificadaAlta (7.5)0.96%—Bosch Bf-os1/8/202217/6/2026
BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device password.
ModificadaAlta (8.8)1.0%—Bosch Pra-es8p2s Firmware23/6/202217/6/2026
The user access rights validation in the web server of the Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 was insufficient. This would allow a non-administrator user to obtain administrator user access rights.
ModificadaCrítica (9.8)0.77%—Bosch Pra-es8p2s Firmware23/6/202217/6/2026
The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 runs its web server with root privilege. In combination with CVE-2022-23534 this could give an attacker root access to the switch.
Orbitaley — Vulnerabilidades