Bosch PSIRT Security Advisories
Information about security vulnerabilities affecting Bosch products.
2025
| Security Advisory ID | Assigned CVE IDs | CVSS Score* | Affected Bosch Products | Title | Publication Date | Last Update | 
|---|---|---|---|---|---|---|
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						8.0
					 | Affected Bosch Products 
 
 | Title 
						Vulnerabilities in ctrlX OS - Setup
					 | Publication Date 
						2025-08-14
					 | Last Update 
						2025-08-14
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						7.5
					 | Affected Bosch Products 
 
 | Title 
						Denial of Service on Rexroth Fieldbus Couplers | Publication Date 
						2025-08-14
					 | Last Update 
						2025-08-14
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						10.0
					 | Affected Bosch Products 
 
 | Title 
						Remote Code Execution in Telex RDC Server and RTS VLink Virtual Matrix
					 | Publication Date 
						2025-06-10
					 | Last Update 
						2025-06-10
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						8.8
					 | Affected Bosch Products 
 
 | Title 
						Multiple ctrlX OS vulnerabilities
					 | Publication Date 
						2025-04-25
					 | Last Update 
						2025-04-25
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						7.8
					 | Affected Bosch Products 
 
 | Title 
						Unquoted Service Path Enumeration on SMCWatchDog Agent
					 | Publication Date 
						2025-01-15
					 | Last Update 
						2025-01-15
					 | 
2024
| Security Advisory ID | Assigned CVE IDs | CVSS Score* | Affected Bosch Products | Title | Publication Date | Last Update | 
|---|---|---|---|---|---|---|
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						7.5
					 | Affected Bosch Products 
 
 | Title 
						DoS vulnerability on IndraDrive
					 | Publication Date 
						2024-10-31
					 | Last Update 
						2024-10-31
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						7.5
					 | Affected Bosch Products 
 
 | Title 
						Unrestricted resource consumption in BVMS
					 | Publication Date 
						2024-10-16
					 | Last Update 
						2024-10-16
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.8
					 | Affected Bosch Products 
 
 | Title 
						Multiple vulnerabilites in libexpat affecting PRC7000
					 | Publication Date 
						2024-10-02
					 | Last Update 
						2024-10-02
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						8.4
					 | Affected Bosch Products 
 
 | Title 
						Sensitive information disclosure in Bosch Configuration Manager
					 | Publication Date 
						2024-10-01
					 | Last Update 
						2024-10-01
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						7.5
					 | Affected Bosch Products 
 
 | Title 
						Unauthenticated information leak in Bosch IP cameras
					 | Publication Date 
						2024-08-21
					 | Last Update 
						2024-08-21
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						8.6
					 | Affected Bosch Products 
 
 | Title 
						Multiple Curl vulnerabilities in the Git for Windows component of Bosch DIVAR IP all-in-one Devices
					 | Publication Date 
						2024-08-07
					 | Last Update 
						2024-08-07
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						8.1
					 | Affected Bosch Products 
 
 | Title 
						"regreSSHion" OpenSSH vulnerability in PRC7000
					 | Publication Date 
						2024-07-19
					 | Last Update 
						2024-07-19
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						6.5
					 | Affected Bosch Products 
 
 | Title 
						TI Bluetooth stack can fail to generate a resolvable Random Private Address (RPA) leading to DoS for already bonded peer devices
					 | Publication Date 
						2024-05-28
					 | Last Update 
						2024-05-31
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.8
					 | Affected Bosch Products 
 
 | Title 
						Remote code execution vulnerability has been found over an insecure connection in the Praesensa Logging Application, Praesideo Logging Application and Praesideo PC Call Station
					 | Publication Date 
						2024-05-15
					 | Last Update 
						2024-05-15
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						8.8
					 | Affected Bosch Products 
 
 | Title 
						Command Injection in Bosch Network Synchronizer
					 | Publication Date 
						2024-03-20
					 | Last Update 
						2024-04-24
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						7.3
					 | Affected Bosch Products 
 
 | Title 
						RPS and RPS-LITE operator and communication process vulnerabilities.
					 | Publication Date 
						2024-03-13
					 | Last Update 
						2024-03-13
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						7.8
					 | Affected Bosch Products 
 
 | Title 
						BVMS affected by Autodesk Design Review Multiple Vulnerabilities
					 | Publication Date 
						2024-03-13
					 | Last Update 
						2024-03-13
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.8
					 | Affected Bosch Products 
 
 | Title 
						Multiple OpenSSL vulnerabilities in BVMS
					 | Publication Date 
						2024-03-06
					 | Last Update 
						2024-03-06
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.8
					 | Affected Bosch Products 
 
 | Title 
						Git for Windows Multiple Security Vulnerabilities in Bosch DIVAR IP all-in-one Devices
					 | Publication Date 
						2024-03-06
					 | Last Update 
						2024-03-06
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						8.3
					 | Affected Bosch Products 
 
 | Title 
						Open Port 8899 in BCC Thermostat Product
					 | Publication Date 
						2024-01-09
					 | Last Update 
						2024-01-09
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						8.8
					 | Affected Bosch Products 
 
 | Title 
						Multiple vulnerabilities in Nexo cordless nutrunner
					 | Publication Date 
						2024-01-08
					 | Last Update 
						2024-01-29
					 | 
2023
| Security Advisory ID | Assigned CVE IDs | CVSS Score* | Affected Bosch Products | Title | Publication Date | Last Update | 
|---|---|---|---|---|---|---|
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						7.2
					 | Affected Bosch Products 
 
 | Title 
						Command injection vulnerability in Bosch IP Cameras
					 | Publication Date 
						2023-12-13
					 | Last Update 
						2023-12-13
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						7.5
					 | Affected Bosch Products 
 
 | Title 
						Denial of Service vulnerability in Bosch BT software products
					 | Publication Date 
						2023-12-13
					 | Last Update 
						2023-12-13
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						8.8
					 | Affected Bosch Products 
 
 | Title 
						Vulnerability in SICK Flexi Soft Gateway
					 | Publication Date 
						2023-10-24
					 | Last Update 
						2023-10-24
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						8.8
					 | Affected Bosch Products 
 
 | Title 
						Multiple vulnerabilities on ctrlX HMI / WR21
					 | Publication Date 
						2023-10-20
					 | Last Update 
						2023-11-21
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						8.4
					 | Affected Bosch Products 
 
 | Title 
						Remote Code Execution in RTS VLink Virtual Matrix
					 | Publication Date 
						2023-08-30
					 | Last Update 
						2023-08-30
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.8
					 | Affected Bosch Products 
 
 | Title 
						Multiple Vulnerabilities PRA-ES8P2S Ethernet-Switch
					 | Publication Date 
						2023-07-26
					 | Last Update 
						2023-07-26
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						7.5
					 | Affected Bosch Products 
 
 | Title 
						Vulnerability in the interface module SLC-0-GPNT00300
					 | Publication Date 
						2023-07-04
					 | Last Update 
						2023-07-04
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						5.9
					 | Affected Bosch Products 
 
 | Title 
						Security Advisory for the FL MGUARD family of devices
					 | Publication Date 
						2023-07-04
					 | Last Update 
						2023-07-04
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						8.1
					 | Affected Bosch Products 
 
 | Title 
						Update in Cybersecurity Guidebook of BIS on Permission Settings for Network Share
					 | Publication Date 
						2023-06-28
					 | Last Update 
						2023-06-28
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						5.3
					 | Affected Bosch Products 
 
 | Title 
						Information Disclosure Vulnerability in Bosch IP cameras
					 | Publication Date 
						2023-06-28
					 | Last Update 
						2023-12-13
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						4.9
					 | Affected Bosch Products 
 
 | Title 
						Possible damage of secure element in Bosch IP cameras
					 | Publication Date 
						2023-05-31
					 | Last Update 
						2023-05-31
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.8
					 | Affected Bosch Products 
 
 | Title 
						.NET Remote Code Execution Vulnerability in BVMS, BIS and AMS
					 | Publication Date 
						2023-05-24
					 | Last Update 
						2023-05-24
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						4.6
					 | Affected Bosch Products 
 
 | Title 
						Vulnerability in Wiegand card data interpretation
					 | Publication Date 
						2023-05-24
					 | Last Update 
						2023-05-24
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						7.1
					 | Affected Bosch Products 
 
 | Title 
						Unrestricted SSH port forwarding in BVMS
					 | Publication Date 
						2023-05-24
					 | Last Update 
						2023-05-24
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.8
					 | Affected Bosch Products 
 
 | Title 
						Use of Telnet in the interface module SLC-0-GPNT00300
					 | Publication Date 
						2023-04-28
					 | Last Update 
						2023-04-28
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						7.6
					 | Affected Bosch Products 
 
 | Title 
						Insecure authentication in B420 legacy communication module
					 | Publication Date 
						2023-04-26
					 | Last Update 
						2023-04-26
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						7.5
					 | Affected Bosch Products 
 
 | Title 
						Vulnerability in routers FL MGUARD and TC MGUARD
					 | Publication Date 
						2023-03-03
					 | Last Update 
						2023-03-03
					 | 
2022
| Security Advisory ID | Assigned CVE IDs | CVSS Score* | Affected Products | Title | Publication Date | Last Update | 
|---|---|---|---|---|---|---|
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.8
					 | Affected Products 
 
 | Title 
						Multiple Vulnerabilities PRA-ES8P2S Ethernet-Switch
					 | Publication Date 
						2022-11-23
					 | Last Update 
						2023-06-28
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						5.8
					 | Affected Products 
 
 | Title 
						Multiple Cross Site Scripting vulnerabilities in Bosch VIDEOJET multi 4000
					 | Publication Date 
						2022-10-19
					 | Last Update 
						2023-01-18
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.8
					 | Affected Products 
 
 | Title 
						Multiple Vulnerabilities in NetApp DSA E2800 series
					 | Publication Date 
						2022-10-19
					 | Last Update 
						2022-12-07
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						7.4
					 | Affected Products 
 
 | Title 
						Information Disclosure in VIDEOJET Decoder and Operator Client application in BVMS
					 | Publication Date 
						2022-09-21
					 | Last Update 
						2022-09-21
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						7.8
					 | Affected Products 
 
 | Title 
						SafeLogic Designer vulnerabilities
					 | Publication Date 
						2022-08-11
					 | Last Update 
						2022-08-11
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.8
					 | Affected Products 
 
 | Title 
						Multiple Vulnerabilities in BF-OS
					 | Publication Date 
						2022-08-01
					 | Last Update 
						2022-11-03
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.8
					 | Affected Products 
 
 | Title 
						Multiple Vulnerabilities PRA-ES8P2S Ethernet-Switch
					 | Publication Date 
						2022-06-22
					 | Last Update 
						2023-02-08
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						8.1
					 | Affected Products 
 
 | Title 
						Vulnerabilities in the communication protocol of the PLC runtime
					 | Publication Date 
						2022-05-02
					 | Last Update 
						2022-10-11
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						7.5
					 | Affected Products 
 
 | Title 
						Vulnerability in routers FL MGUARD and TC MGUARD
					 | Publication Date 
						2022-04-27
					 | Last Update 
						2022-04-27
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.8
					 | Affected Products 
 
 | Title 
						Improper Control of Generation of Code in Bosch MATRIX
					 | Publication Date 
						2022-04-27
					 | Last Update 
						2022-04-27
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.8
					 | Affected Products 
 
 | Title 
						Multiple ctrlX CORE vulnerabilities
					 | Publication Date 
						2022-04-20
					 | Last Update 
						2022-04-20
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						6.8
					 | Affected Products 
 
 | Title 
						Buffer Overflow Vulnerability in Recovery Image
					 | Publication Date 
						2022-03-30
					 | Last Update 
						2022-09-07
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.8
					 | Affected Products 
 
 | Title 
						Bosch Fire Monitoring System (FSM) affected by log4net Vulnerability
					 | Publication Date 
						2022-03-23
					 | Last Update 
						2024-07-03
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.8
					 | Affected Products 
 
 | Title 
						Improper Restriction of XML External Entity Reference in BVMS
					 | Publication Date 
						2022-03-16
					 | Last Update 
						2022-03-16
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						6.1
					 | Affected Products 
 
 | Title 
						Injection of arbitrary HTML code in Bosch Video Security Android App
					 | Publication Date 
						2022-01-26
					 | Last Update 
						2022-09-07
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						8.8
					 | Affected Products 
 
 | Title 
						Multiple vulnerabilities in Bosch AMC2 (Access Modular Controller)
					 | Publication Date 
						2022-01-19
					 | Last Update 
						2022-01-28
					 | 
2021
| Security Advisory ID | Assigned CVE IDs | CVSS Score* | Affected Products | Title | Publication Date | Last Update | 
|---|---|---|---|---|---|---|
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						10.0
					 | Affected Products 
 
 | Title 
						Log4j Vulnerabilities - Impact on PRAESENSA Advanced Public Address Server (PRA-APAS)
					 | Publication Date 
						2021-12-22
					 | Last Update 
						2021-12-22
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.0
					 | Affected Products 
 
 | Title 
						Apache Log4j Vulnerabilities - Impact on Bosch Rexroth Products
					 | Publication Date 
						2021-12-21
					 | Last Update 
						2022-01-10
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.1
					 | Affected Products 
 
 | Title 
						Multiple Vulnerabilities in Bosch BT software products
					 | Publication Date 
						2021-12-08
					 | Last Update 
						2021-12-08
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						10.0
					 | Affected Products 
 
 | Title 
						Multiple vulnerabilities in Rexroth IndraMotion and IndraLogic series
					 | Publication Date 
						2021-10-04
					 | Last Update 
						2022-08-25
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						7.5
					 | Affected Products 
 
 | Title 
						Cross Site Request Forgery (CSRF) vulnerability in Bosch IP cameras
					 | Publication Date 
						2021-08-04
					 | Last Update 
						2021-10-07
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.8
					 | Affected Products 
 
 | Title 
						Vulnerabilities in CODESYS V2 runtime systems
					 | Publication Date 
						2021-07-20
					 | Last Update 
						2021-07-20
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.8
					 | Affected Products 
 
 | Title 
						Vulnerabilities in CODESYS V2 runtime systems
					 | Publication Date 
						2021-07-09
					 | Last Update 
						2021-07-09
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.8
					 | Affected Products 
 
 | Title 
						Multiple vulnerabilities in Bosch IP cameras
					 | Publication Date 
						2021-06-09
					 | Last Update 
						2021-06-09
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						8.8
					 | Affected Products 
 
 | Title 
						Several Vulnerabilities in Bosch B426, B426-CN/B429-CN, and B426-M
					 | Publication Date 
						2021-05-28
					 | Last Update 
						2023-02-03
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						7.3
					 | Affected Products 
 
 | Title 
						Vulnerability in the routing protocol of the PLC runtime
					 | Publication Date 
						2021-05-19
					 | Last Update 
						2021-05-19
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.8
					 | Affected Products 
 
 | Title 
						ctrlX CORE - IDE App affected by OpenSSL and Python Vulnerabilities
					 | Publication Date 
						2021-04-30
					 | Last Update 
						2021-04-30
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						n/a
					 | Affected Products 
 
 | Title 
						FTP Backdoor for Rexroth Fieldbus Couplers S20 and Inline
					 | Publication Date 
						2021-04-30
					 | Last Update 
						2021-04-30
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.1
					 | Affected Products 
 
 | Title 
						ctrlX Multiple Vulnerabilities
					 | Publication Date 
						2021-04-23
					 | Last Update 
						2021-04-23
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						7.5
					 | Affected Products 
 
 | Title 
						Denial of Service in Rexroth ActiveMover using EtherNet/IP protocol
					 | Publication Date 
						2021-03-31
					 | Last Update 
						2021-03-31
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						7.5
					 | Affected Products 
 
 | Title 
						Denial of Service in Rexroth ActiveMover using Profinet protocol
					 | Publication Date 
						2021-03-31
					 | Last Update 
						2022-01-26
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						7.8
					 | Affected Products 
 
 | Title 
						Uncontrolled Search Path Element in Multiple Bosch Products
					 | Publication Date 
						2021-03-24
					 | Last Update 
						2021-03-30
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						4.2
					 | Affected Products 
 
 | Title 
						Side Channel Key Extraction Vulnerability in Bosch IP Cameras and Encoders
					 | Publication Date 
						2021-03-03
					 | Last Update 
						2021-03-03
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						7.8
					 | Affected Products 
 
 | Title 
						Privilege Escalation via sudo and Linux kernel in Bosch Rexroth Products
					 | Publication Date 
						2021-02-24
					 | Last Update 
						2021-02-24
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						9.8
					 | Affected Products 
 
 | Title 
						Denial of Service in Rexroth ID 200/C-ETH using EtherNet/IP Protocol
					 | Publication Date 
						2021-01-27
					 | Last Update 
						2021-01-27
					 | 
| Security Advisory ID | Assigned CVE IDs 
 
 | CVSS Score* 
						10
					 | Affected Products 
 
 | Title 
						Two Vulnerabilities in Bosch Fire Monitoring System (FSM)
					 | Publication Date 
						2021-01-20
					 | Last Update 
						2024-07-03
					 | 
2020
| Security Advisory ID | Assigned CVE IDs | CVSS Score* | Affected Products | Title | Publication Date | Last Update | 
|---|---|---|---|---|---|---|
| Security Advisory ID | Assigned CVE IDs 
						CVE-2020-1971
					 | CVSS Score* 
						5.9
					 | Affected Products 
 
 | Title 
						ctrlX Products affected by OpenSSL Vulnerability CVE-2020-1971
					 | Publication Date 
						2020-12-18
					 | Last Update 
						2021-01-21
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2019-5105 CVE-2020-7052 | CVSS Score* 
						7.5
					 | Affected Products 
 
 | Title 
						Denial of Service in PLC Runtime affecting Rexroth IndraMotion Products
					 | Publication Date 
						2020-12-16
					 | Last Update 
						2020-12-16
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2019-18858 CVE-2019-5105 CVE-2019-9010 CVE-2019-9012 CVE-2019-9013 CVE-2020-10245 | CVSS Score* 
						10.0
					 | Affected Products 
 
 | Title 
						Multiple Vulnerabilities in 3S CODESYS Runtime in Rexroth PRC7000
					 | Publication Date 
						2020-12-16
					 | Last Update 
						2020-12-16
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2019-0708
					 | CVSS Score* 
						9.8
					 | Affected Products 
 
 | Title 
						Remote Desktop Services Remote Code Execution Vulnerability in Rexroth Industrial PCs
					 | Publication Date 
						2020-10-13
					 | Last Update 
						2020-10-13
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2020-6776 CVE-2020-6777 CVE-2020-15688 | CVSS Score* 
						8.8
					 | Affected Products 
 
 | Title 
						Vulnerabilities in Bosch PRAESIDEO and PRAESENSA
					 | Publication Date 
						2020-09-30
					 | Last Update 
						2020-09-30
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2020-14513 CVE-2020-14519 CVE-2020-14509 CVE-2020-14517 CVE-2020-16233 CVE-2020-14515 | CVSS Score* 
						10.0
					 | Affected Products 
 
 | Title 
						WIBU Systems CodeMeter Runtime Vulnerabilities in Rexroth Products
					 | Publication Date 
						2020-09-25
					 | Last Update 
						2020-09-25
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2020-6781
					 | CVSS Score* 
						6.8
					 | Affected Products 
 
 | Title 
						Improper Certificate Validation in Bosch Smart Home System App for iOS
					 | Publication Date 
						2020-08-25
					 | Last Update 
						2020-08-25
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2017-0144 CVE-2019-0708 CVE-2020-6774 | CVSS Score* 
						9.8
					 | Affected Products 
 
 | Title 
						Multiple Vulnerabilities in Bosch Recording Station (BRS)
					 | Publication Date 
						2020-05-27
					 | Last Update 
						2020-05-27
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2018-16994
					 | CVSS Score* 
						7.5
					 | Affected Products 
 
 | Title 
						Denial of Service in Rexroth Fieldbus Coupler S20-PN-BK+/S20-ETH-BK
					 | Publication Date 
						2020-03-16
					 | Last Update 
						2020-03-16
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2020-6770
					 | CVSS Score* 
						10.0
					 | Affected Products 
 
 | Title 
						Deserialization of Untrusted Data in Bosch BVMS Mobile Video Service
					 | Publication Date 
						2020-01-29
					 | Last Update 
						2020-01-29
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2020-6769
					 | CVSS Score* 
						10.0
					 | Affected Products 
 
 | Title 
						Missing Authentication for Critical Function in Bosch Video Streaming Gateway
					 | Publication Date 
						2020-01-29
					 | Last Update 
						2020-01-29
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2020-6768
					 | CVSS Score* 
						8.6
					 | Affected Products 
 
 | Title 
						Path Traversal in Bosch Video Management System NoTouch deployment
					 | Publication Date 
						2020-01-29
					 | Last Update 
						2020-02-11
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2020-6767 | CVSS Score* 
						7.7
					 | Affected Products 
 
 | Title 
						Path Traversal in Bosch Video Management System
					 | Publication Date 
						2020-01-29
					 | Last Update 
						2020-02-11
					 | 
2019
| Security Advisory ID | Assigned CVE IDs | CVSS Score* | Affected Products | Title | Publication Date | Last Update | 
|---|---|---|---|---|---|---|
| Security Advisory ID | Assigned CVE IDs 
						CVE-2019-11899
					 | CVSS Score* 
						8.8
					 | Affected Products 
						Bosch Access Professional Edition
					 | Title 
						Improper Access Control in Access Professional Edition 3.7 downwards
					 | Publication Date 
						2019-09-11
					 | Last Update 
						2019-09-11
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2019-11898
					 | CVSS Score* 
						9.9
					 | Affected Products 
						Bosch Access Professional Edition
					 | Title 
						Hard-coded Credentials in Access Professional Edition 3.7 downwards
					 | Publication Date 
						2019-09-11
					 | Last Update 
						2019-09-11
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2019-1181 CVE-2019-1182 | CVSS Score* 
						9.8
					 | Affected Products 
 
 | Title 
						Vulnerability for Windows Remote Desktop Services (RDP) Remote Code Execution
					 | Publication Date 
						2019-09-03
					 | Last Update 
						2019-09-03
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2019-11601 CVE-2019-11897 CVE-2019-11602 CVE-2019-11603 | CVSS Score* 
						9.1
					 | Affected Products 
 
 | Title 
						Multiple Vulnerabilities in ProSyst mBS SDK and Bosch IoT Gateway Software
					 | Publication Date 
						2019-08-19
					 | Last Update 
						2020-03-16
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2019-12256 CVE-2019-12257 CVE-2019-12255 CVE-2019-12260 CVE-2019-12261 CVE-2019-12263 CVE-2019-12258 CVE-2019-12259 CVE-2019-12262 CVE-2019-12264 CVE-2019-12265 | CVSS Score* 
						9.8
					 | Affected Products 
 
 | Title 
						VxWorks security updates in Bosch Rexroth controllers
					 | Publication Date 
						2019-08-08
					 | Last Update 
						2019-08-08
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2019-0708
					 | CVSS Score* 
						9.8
					 | Affected Products 
 
 | Title 
						Vulnerability for Windows Remote Desktop Services (RDP) Remote Code Execution
					 | Publication Date 
						2019-06-12
					 | Last Update 
						2019-06-12
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2019-11601 CVE-2019-11602 CVE-2019-11603 CVE-2019-11891 CVE-2019-11892 CVE-2019-11893 CVE-2019-11894 CVE-2019-11895 CVE-2019-11896 CVE-2019-11897 | CVSS Score* 
						9.1
					 | Affected Products 
						Bosch Smart Home Controller
					 | Title 
						Multiple Vulnerabilities in Bosch Smart Home Controller
					 | Publication Date 
						2019-05-29
					 | Last Update 
						2019-05-29
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2019-11684
					 | CVSS Score* 
						9.9
					 | Affected Products 
						Bosch Video Recording Manager
					 | Title 
						Unauthenticated Certificate Access in Video Recording Manager
					 | Publication Date 
						2019-05-09
					 | Last Update 
						2022-02-10
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2019-6958
					 | CVSS Score* 
						9.8
					 | Affected Products 
 
 | Title 
						Improper Access Control in Bosch Security Systems Software for Video, PSIM and Access Control Systems
					 | Publication Date 
						2019-04-03
					 | Last Update 
						2019-04-03
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2019-6957
					 | CVSS Score* 
						9.8
					 | Affected Products 
 
 | Title 
						Buffer Overflow in Bosch Security Systems Software for Video, PSIM and Access
					 | Publication Date 
						2019-04-03
					 | Last Update 
						2019-04-03
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2019-8952
					 | CVSS Score* 
						4.9
					 | Affected Products 
						Hardware:
	 
 Software: 
 
 | Title 
						Path Traversal Vulnerability in Video Recording Manager
					 | Publication Date 
						2019-04-03
					 | Last Update 
						2019-04-03
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2019-8951
					 | CVSS Score* 
						6.1
					 | Affected Products 
						Hardware:
	 
 Software: 
 
 | Title 
						Open Redirect Vulnerability in Video Recording Manager
					 | Publication Date 
						2019-04-03
					 | Last Update 
						2019-04-03
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2019-7729
					 | CVSS Score* 
						4.8
					 | Affected Products 
						Smart Camera App for Android < 1.3.1
					 | Title 
						Insecure Permissions in Smart Camera App for Android
					 | Publication Date 
						2019-02-22
					 | Last Update 
						2019-02-22
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2019-7728
					 | CVSS Score* 
						8.3
					 | Affected Products 
						Smart Camera App for Android < 1.3.1
					 | Title 
						Improper Certificate Validation in Smart Camera App for Android
					 | Publication Date 
						2019-02-22
					 | Last Update 
						2019-02-22
					 | 
| Security Advisory ID | Assigned CVE IDs | CVSS Score* 
						9.8
					 | Affected Products 
 
 | Title 
						Bosch Rexroth IndraWorks Operation (WinStudio) Security Advisory
					 | Publication Date 
						2019-02-18
					 | Last Update 
						2019-02-18
					 | 
| Security Advisory ID | Assigned CVE IDs | CVSS Score* 
						10
					 | Affected Products 
						Bosch digital recorder DVR 400 & 600 series
					 | Title 
						DIVAR 400 & 600 series Vulnerability
					 | Publication Date 
						2019-01-22
					 | Last Update 
						2019-01-22
					 | 
2018
| Security Advisory ID | Assigned CVE IDs | CVSS Score* | Affected Products | Title | Publication Date | Last Update | 
|---|---|---|---|---|---|---|
| Security Advisory ID | Assigned CVE IDs 
						CVE-2018-20299
					 | CVSS Score* 
						9.4
					 | Affected Products 
 
 | Title 
						Bosch Smart Home Camera Vulnerability
					 | Publication Date 
						2018-12-18
					 | Last Update 
						2018-12-20
					 | 
| Security Advisory ID | Assigned CVE IDs 
						CVE-2018-19036
					 | CVSS Score* 
						9.4
					 | Affected Products 
 
 | Title 
						Bosch IP Camera Vulnerability
					 | Publication Date 
						2018-12-12
					 | Last Update 
						2022-02-10
					 | 
| Security Advisory ID | Assigned CVE IDs | CVSS Score* 
						6.5
					 | Affected Products 
 
 | Title 
						Bosch Access Easy Controller 2.1
					 | Publication Date 
						2018-12-03
					 | Last Update 
						2018-12-03
					 | 
| Security Advisory ID | Assigned CVE IDs | CVSS Score* 
						9.8
					 | Affected Products 
 
 | Title 
						Bosch Rexroth IndraWorks Operation (WinStudio) Security Advisory
					 | Publication Date 
						2018-11-27
					 | Last Update 
						2018-11-27
					 | 
2017
| Security Advisory ID | Assigned CVE IDs | CVSS Score* | Affected Products | Title | Publication Date | Last Update | 
|---|---|---|---|---|---|---|
| Security Advisory ID | Assigned CVE IDs | CVSS Score* 
						6.5
					 | Affected Products 
						Bosch Drivelog Connector
					 | Title 
						Bosch Drivelog Connector
					 | Publication Date 
						2017-04-13
					 | Last Update 
						2017-04-13
					 | 
| Security Advisory ID | Assigned CVE IDs | CVSS Score* 
						2.9
					 | Affected Products 
						Bosch BMA222E
					 | Title 
						Bosch BMA222E Acoustic Resonance Interference
					 | Publication Date 
						2017-03-14
					 | Last Update 
						2017-03-14
					 | 
2016
| Security Advisory ID | Assigned CVE IDs | CVSS Score* | Affected Products | Title | Publication Date | Last Update | 
|---|---|---|---|---|---|---|
| Security Advisory ID | Assigned CVE IDs | CVSS Score* 
						6.4
					 | Affected Products 
						Bosch Rexroth BLADEcontrol-WebVIS
					 | Title 
						Bosch Rexroth BLADEcontrol-WebVIS
					 | Publication Date 
						2016-07-22
					 | Last Update 
						2017-03-14
					 | 
Atom / RSS Feeds
Subscribe to our feed(s) to be notified about new Security Advisories.
Bosch PSIRT
Search our S/MIME key here
Fingerprint: 87:F1:6F:70:60:D2:94:83:82:AC:69:F5:46:86:7C:80:7F:86:1D:F0
Find our PGP Key here
Fingerprint: 0C19 7DE3 6D10 6637 CFDA DFC9 69A8 FAA2 DBBE 481F