Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

138 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.4%—Bosch Pra-es8p2s Firmware23/6/202217/6/2026
The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command injection through its diagnostics web interface. This allows execution of shell commands.
ModificadaAlta (7.2)1.6%—Bosch Autodome IP 4000i FirmwareBosch Autodome IP 5000i FirmwareBosch Autodome IP Starlight 5000i FirmwareBosch Autodome IP Starlight 7000i Firmware+6430/3/202217/6/2026
A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in…
ModificadaAlta (7.2)1.6%—Bosch Autodome IP 4000i FirmwareBosch Autodome IP 5000i FirmwareBosch Autodome IP Starlight 5000i FirmwareBosch Autodome IP Starlight 7000i Firmware+6430/3/202217/6/2026
A specially crafted TCP/IP packet may cause a camera recovery image telnet interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in…
ModificadaMedia (6.1)0.56%—Bosch Video Security28/1/202217/6/2026
HTML code injection vulnerability in Android Application, Bosch Video Security, version 3.2.3. or earlier, when successfully exploited allows an attacker to inject random HTML code into a component loaded by WebView, thus allowing the Application to display web resources controlled by the attacker.
ModificadaAlta (7.8)0.24%—Bosch Amc2 FirmwareBosch Access Management SystemBosch Access Professional EditionBosch Building Integration System19/1/202217/6/2026
The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a password protection on configured devices to restrict access to the configuration of an AMC2. An attacker can circumvent this protection and make unauthorized changes to…
ModificadaAlta (7.1)0.14%—Bosch Amc2 FirmwareBosch Access Management SystemBosch Access Professional EditionBosch Building Integration System19/1/202217/6/2026
Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An attacker could retrieve the key from the firmware to decrypt network traffic between the AMC2 and the host system. Thus, an attacker can exploit this vulnerability to decrypt and modify network…
ModificadaAlta (7.2)1.4%—Bosch Video Management SystemBosch Video Recording ManagerBosch Videojet Decoder 7513 FirmwareBosch Videojet Decoder 8000 Firmware8/12/202117/6/2026
A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in system context. This issue also affects installations of the VRM, DIVAR IP, BVMS with VRM installed, the VIDEOJET decoder (VJD-7513 and VJD-8000).
ModificadaMedia (6.5)0.83%—Bosch Video Management SystemBosch Video Recording Manager8/12/202117/6/2026
By executing a special command, an user with administrative rights can get access to extended debug functionality on the VRM allowing an impact on integrity or availability of the installed software. This issue also affects installations of the DIVAR IP and BVMS with VRM installed.
ModificadaMedia (6.1)0.51%—Bosch Video Management SystemBosch Video Recording Manager8/12/202117/6/2026
An error in a page handler of the VRM may lead to a reflected cross site scripting (XSS) in the web-based interface. To exploit this vulnerability an attack must be able to modify the HTTP header that is sent. This issue also affects installations of the DIVAR IP and BVMS with VRM installed.
ModificadaAlta (7.5)1.0%—Bosch Video Management SystemBosch Video Recording ManagerBosch Access Easy Controller FirmwareBosch Access Professional Edition+28/12/202117/6/2026
An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM installation this crash also opens the possibility to send further unauthenticated commands to the service. On some products the interface is only local accessible lowering…
ModificadaAlta (7.5)1.2%—Bosch Rexroth Indramotion MLC L20 FirmwareBosch Rexroth Indramotion MLC L40 FirmwareBosch Rexroth Indramotion MLC L25 FirmwareBosch Rexroth Indramotion MLC L45 Firmware+84/10/202117/6/2026
Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by another unprotected web server…
ModificadaCrítica (9.8)1.2%—Bosch Rexroth Indramotion MLC L20 FirmwareBosch Rexroth Indramotion MLC L40 FirmwareBosch Rexroth Indramotion MLC L25 FirmwareBosch Rexroth Indramotion MLC L45 Firmware+84/10/202117/6/2026
Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login to the system.
ModificadaMedia (6.1)0.63%—Bosch Rexroth Indramotion MLC L20 FirmwareBosch Rexroth Indramotion MLC L40 Firmware4/10/202117/6/2026
The web server is vulnerable to reflected XSS and therefore an attacker might be able to execute scripts on a client’s computer by sending the client a manipulated URL.
ModificadaAlta (7.5)0.60%—Bosch Rexroth Indramotion XLC FirmwareBosch Rexroth Indramotion MLC Firmware4/10/202117/6/2026
The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashing algorithm and therefore allow an attacker to determine the password by using rainbow tables.
ModificadaAlta (8.8)0.49%—Bosch Cpp4 FirmwareBosch Cpp6 FirmwareBosch Aviotec FirmwareBosch Cpp7 Firmware+35/8/202117/6/2026
A vulnerability in the web-based interface allows an unauthenticated remote attacker to trigger actions on an affected system on behalf of another user (CSRF - Cross Site Request Forgery). This requires the victim to be tricked into clicking a malicious link or opening a malicious website while being logged in into…
ModificadaMedia (5.9)0.47%—Bosch B426 Firmware18/6/202117/6/2026
When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5, which will be released on the 30th of June, 2021.
ModificadaAlta (8.8)0.84%—Bosch B426 FirmwareBosch B426-cn FirmwareBosch B429-cn FirmwareBosch B426-m Firmware18/6/202117/6/2026
This vulnerability could allow an attacker to hijack a session while a user is logged in the configuration web page. This vulnerability was discovered by a security researcher in B426 and found during internal product tests in B426-CN/B429-CN, and B426-M and has been fixed already starting from version 3.08 on, which…
ModificadaMedia (6.1)0.56%—Bosch Cpp6 FirmwareBosch Cpp7 FirmwareBosch Cpp7.3 FirmwareBosch Cpp13 Firmware9/6/202117/6/2026
An error in the handling of a page parameter in Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. This issue only affects versions 7.7x and 7.6x. All other versions are not affected.
ModificadaCrítica (9.8)0.86%—Bosch Cpp4 FirmwareBosch Cpp6 FirmwareBosch Cpp7 FirmwareBosch Cpp7.3 Firmware+19/6/202117/6/2026
In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP headers through crafted URLs.
ModificadaMedia (4.9)0.83%—Bosch Cpp4 FirmwareBosch Cpp6 FirmwareBosch Cpp7 FirmwareBosch Cpp7.3 Firmware+19/6/202117/6/2026
An authenticated attacker with administrator rights Bosch IP cameras can call an URL with an invalid parameter that causes the camera to become unresponsive for a few seconds and cause a Denial of Service (DoS).
ModificadaMedia (6.1)0.56%—Bosch Cpp4 FirmwareBosch Cpp6 FirmwareBosch Cpp7 FirmwareBosch Cpp7.3 Firmware+19/6/202117/6/2026
An error in the URL handler Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the camera address can send a crafted link to a user, which will execute javascript code in the context of the user.
ModificadaCrítica (9.1)1.4%—Bosch Cpp6 FirmwareBosch Cpp7 FirmwareBosch Cpp7.3 Firmware9/6/202117/6/2026
A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or change settings of the camera by sending crafted requests to the device. Only devices of the CPP6, CPP7 and CPP7.3 family with firmware 7.70, 7.72, and 7.80 prior to B128 are…
ModificadaAlta (7.8)0.35%—Bosch Video Streaming Gateway25/3/202117/6/2026
Calling an executable through an Uncontrolled Search Path Element in the Bosch Video Streaming Gateway installer up to and including version 6.45.10 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious exe in the same…
ModificadaAlta (7.8)0.35%—Bosch Monitor Wall25/3/202117/6/2026
Loading a DLL through an Uncontrolled Search Path Element in the Bosch Monitor Wall installer up to and including version 10.00.0164 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious DLL in the same directory where the…
ModificadaAlta (7.8)0.35%—Bosch Configuration Manager25/3/202117/6/2026
Loading a DLL through an Uncontrolled Search Path Element in the Bosch Configuration Manager installer up to and including version 7.21.0078 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious DLL in the same directory…
Orbitaley — Vulnerabilidades