Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on the system. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.0.329 and 7.5 and older. This affects Bosch DIVAR IP 3000 and DIVAR IP 7000 if a vulnerable BVMS version is installed.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bosch_video_management_system_mobile_video_service | Bosch | * | 7.5 (including) |
Bosch_video_management_system_mobile_video_service | Bosch | 8.0 (including) | 8.0.0.329 (including) |
Bosch_video_management_system_mobile_video_service | Bosch | 9.0 (including) | 9.0.0.827 (including) |
Bosch_video_management_system_mobile_video_service | Bosch | 10.0 (including) | 10.0.0.1225 (including) |