<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<title>Bosch Building Technologies Security Advisories</title>
	
	<updated>2026-07-31T06:38:18Z</updated>
	<id>https://psirt.bosch.com/security-advisories/bosch-building-technologies-feed.xml</id>
	<link rel="alternate" type="text/html" href="https://psirt.bosch.com"/>
	<subtitle>Bosch Building Technologies Security Advisories</subtitle>
	<rights>Robert Bosch GmbH</rights>
	<entry>
								<updated>2025-11-19T00:00:00</updated>
								<title>OpenSSH DoS due to signal handler race condition</title>
								<content type="html">
							    	
									&lt;p&gt;BOSCH-SA-085467-BT: MAP 5000 is affected by an OpenSSH vulnerability which is enabled in a backwards compatibility mode. It allows remote attackers to cause a denial-of-service (DoS) by crashing the panel.&lt;/p&gt;
								</content>
								<link rel="alternate" type="text/html" href="https://psirt.bosch.com/security-advisories/bosch-sa-085467-bt.html" />
								<id>https://psirt.bosch.com/security-advisories/bosch-sa-085467-bt.html</id>
								<author>
									<name>Robert Bosch GmbH</name>
								</author>
							</entry>
						<entry>
								<updated>2025-11-19T00:00:00</updated>
								<title>Deprecated SSH cryptographic settings</title>
								<content type="html">
							    	
									&lt;p&gt;BOSCH-SA-359440-BT: A security issue has been identified in the Bosch MAP 5000 family of products, which stems from the use of insecure cryptographic algorithms in the SSH service configuration. It may expose systems to cryptographic attacks, unauthorized access, or data leakage.&lt;/p&gt;
								</content>
								<link rel="alternate" type="text/html" href="https://psirt.bosch.com/security-advisories/bosch-sa-359440-bt.html" />
								<id>https://psirt.bosch.com/security-advisories/bosch-sa-359440-bt.html</id>
								<author>
									<name>Robert Bosch GmbH</name>
								</author>
							</entry>
						<entry>
								<updated>2025-11-19T00:00:00</updated>
								<title>Multiple vulnerabilities in MAP intrusion panel</title>
								<content type="html">
							    	
									&lt;p&gt;BOSCH-SA-688644-BT:  The MAP 5000 is susceptible to multiple vulnerabilities.  Vulnerability CVE-2021-3449 can lead to system crashes caused by DoS attacks. Such vulnerabilities allow malicious actors to disrupt service, resulting in downtime and loss of access for legitimate users, which can severely impact business operations.  Vulnerability CVE-2023-48795 constitutes a weakness in secure communication protocols, potentially exposing sensitive data to unauthorized access and manipulation. Such vulnerabilities compromise the confidentiality of information transmitted over the network and can lead to integrity issues, where data may be altered without detection.&lt;/p&gt;
								</content>
								<link rel="alternate" type="text/html" href="https://psirt.bosch.com/security-advisories/bosch-sa-688644-bt.html" />
								<id>https://psirt.bosch.com/security-advisories/bosch-sa-688644-bt.html</id>
								<author>
									<name>Robert Bosch GmbH</name>
								</author>
							</entry>
						<entry>
								<updated>2025-11-19T00:00:00</updated>
								<title>Weak Diffie-Hellman in TLS protocol</title>
								<content type="html">
							    	
									&lt;p&gt;BOSCH-SA-873110-BT: The TLS server implementation in MAP 5000 was found to use outdated settings for cryptography. The resulting weakness in the TLS protocol key exchange (Diffie-Hellman) allows an attacker to passively decrypt or intercept and manipulate secured communication. It is estimated that the required resources for a successful attack restrict the attacker profile to state-level adversaries and well-funded criminal organizations. &lt;/p&gt;
								</content>
								<link rel="alternate" type="text/html" href="https://psirt.bosch.com/security-advisories/bosch-sa-873110-bt.html" />
								<id>https://psirt.bosch.com/security-advisories/bosch-sa-873110-bt.html</id>
								<author>
									<name>Robert Bosch GmbH</name>
								</author>
							</entry>
						<entry>
								<updated>2025-06-10T00:00:00</updated>
								<title>Remote Code Execution in Telex RDC Server and RTS VLink Virtual Matrix</title>
								<content type="html">
							    	
									&lt;p&gt;BOSCH-SA-992447-BT: A security vulnerability has been uncovered in the REST API of the Telex Remote Dispatch Console Server and the RTS VLink Virtual Matrix Software. The vulnerability will allow a Remote Code Execution (RCE) attack.  All versions &lt; 1.3.0 of the Telex Remote Dispatch Console Server are affected by this vulnerability.  Versions v5 and v6 (&lt; 6.6.0) of the RTS VLink Virtual Matrix Software are affected by this vulnerability. Older versions (v4 and lower) are not affected.  The vulnerability has been uncovered and disclosed responsibly by external researcher Omer Shaik. &lt;/p&gt;
								</content>
								<link rel="alternate" type="text/html" href="https://psirt.bosch.com/security-advisories/bosch-sa-992447-bt.html" />
								<id>https://psirt.bosch.com/security-advisories/bosch-sa-992447-bt.html</id>
								<author>
									<name>Robert Bosch GmbH</name>
								</author>
							</entry>
						<entry>
								<updated>2025-01-15T00:00:00</updated>
								<title>Unquoted Service Path Enumeration on SMCWatchDog Agent</title>
								<content type="html">
							    	
									&lt;p&gt;BOSCH-SA-904062-BT: An unquoted service path enumeration vulnerability on SMCWatchDog agent has been found affecting the DIVAR IP all-in-one 7000 (DIP-72xx) devices. This vulnerability can allow a local attacker to gain elevated privileges.&lt;/p&gt;
								</content>
								<link rel="alternate" type="text/html" href="https://psirt.bosch.com/security-advisories/bosch-sa-904062-bt.html" />
								<id>https://psirt.bosch.com/security-advisories/bosch-sa-904062-bt.html</id>
								<author>
									<name>Robert Bosch GmbH</name>
								</author>
							</entry>
						<entry>
								<updated>2024-10-16T00:00:00</updated>
								<title>Unrestricted resource consumption in BVMS</title>
								<content type="html">
							    	
									&lt;p&gt;BOSCH-SA-162032-BT: A vulnerability has been identified in the Bosch VMS Central Server concerning unrestricted resource consumption, leading to excessive use of disk space. The uncontrolled resource consumption can lead to a significant impact on the availability and performance of the affected system. This can result in the inability to store new data, process incoming requests, and perform essential system functions. In severe cases, it may lead to system crashes and data loss.
&lt;/p&gt;
								</content>
								<link rel="alternate" type="text/html" href="https://psirt.bosch.com/security-advisories/bosch-sa-162032-bt.html" />
								<id>https://psirt.bosch.com/security-advisories/bosch-sa-162032-bt.html</id>
								<author>
									<name>Robert Bosch GmbH</name>
								</author>
							</entry>
						<entry>
								<updated>2024-10-01T00:00:00</updated>
								<title>Sensitive information disclosure in Bosch Configuration Manager</title>
								<content type="html">
							    	
									&lt;p&gt;BOSCH-SA-981803-BT: A vulnerability was discovered during internal testing of the Bosch Configuration Manager, which may temporarily store sensitive information of the configured system.
&lt;/p&gt;
								</content>
								<link rel="alternate" type="text/html" href="https://psirt.bosch.com/security-advisories/bosch-sa-981803-bt.html" />
								<id>https://psirt.bosch.com/security-advisories/bosch-sa-981803-bt.html</id>
								<author>
									<name>Robert Bosch GmbH</name>
								</author>
							</entry>
						<entry>
								<updated>2024-08-21T00:00:00</updated>
								<title>Unauthenticated information leak in Bosch IP cameras</title>
								<content type="html">
							    	
									&lt;p&gt;BOSCH-SA-659648-BT: A vulnerability was discovered in internal testing of Bosch IP cameras of families CPP13 and CPP14, that allows an unauthenticated attacker to retrieve video analytics event data. No video data is leaked through this vulnerability.
&lt;/p&gt;
								</content>
								<link rel="alternate" type="text/html" href="https://psirt.bosch.com/security-advisories/bosch-sa-659648-bt.html" />
								<id>https://psirt.bosch.com/security-advisories/bosch-sa-659648-bt.html</id>
								<author>
									<name>Robert Bosch GmbH</name>
								</author>
							</entry>
						<entry>
								<updated>2024-08-07T00:00:00</updated>
								<title>Multiple Curl vulnerabilities in the Git for Windows component of Bosch DIVAR IP all-in-one Devices</title>
								<content type="html">
							    	
									&lt;p&gt;BOSCH-SA-587194-BT:  DIVAR IP System Manager is a central user interface that provides an easy system setup, configuration and application software upgrades through an easily accessible web-based application.  Multiple Curl vulnerabilities in the Git for Windows component have been discovered in DIVAR IP System Manager versions prior to 2.3.2, affecting several Bosch DIVAR IP all-in-one models. &lt;/p&gt;
								</content>
								<link rel="alternate" type="text/html" href="https://psirt.bosch.com/security-advisories/bosch-sa-587194-bt.html" />
								<id>https://psirt.bosch.com/security-advisories/bosch-sa-587194-bt.html</id>
								<author>
									<name>Robert Bosch GmbH</name>
								</author>
							</entry>
						
</feed>