CVE-2023-28175

Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access resources within the trusted internal network via a port forwarding request.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:h:bosch:divar_ip_4000:-:*:*:*:*:*:*:*
cpe:2.3:h:bosch:divar_ip_5000:-:*:*:*:*:*:*:*
cpe:2.3:h:bosch:divar_ip_6000:-:*:*:*:*:*:*:*
cpe:2.3:h:bosch:divar_ip_7000:-:*:*:*:*:*:*:*
cpe:2.3:h:bosch:divar_ip_7000_r2:-:*:*:*:*:*:*:*
cpe:2.3:h:bosch:divar_ip_7000_r3:-:*:*:*:*:*:*:*
OR cpe:2.3:a:bosch:video_management_system:*:*:*:*:*:*:*:*
cpe:2.3:a:bosch:video_management_system_viewer:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:bosch:divar_ip_3000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:bosch:divar_ip_3000:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:bosch:divar_ip_6000_firmware:11.1.1:*:*:*:*:*:*:*
cpe:2.3:h:bosch:divar_ip_6000:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:bosch:divar_ip_4000_firmware:11.1.1:*:*:*:*:*:*:*
cpe:2.3:h:bosch:divar_ip_4000:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:bosch:divar_ip_5000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:bosch:divar_ip_5000:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:bosch:divar_ip_7000_r2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:bosch:divar_ip_7000_r2:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:bosch:divar_ip_7000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:bosch:divar_ip_7000:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:bosch:divar_ip_7000_r3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:bosch:divar_ip_7000_r3:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-06-15 11:15

Updated : 2023-07-05 13:25


NVD link : CVE-2023-28175

Mitre link : CVE-2023-28175

CVE.ORG link : CVE-2023-28175


JSON object : View

Products Affected

bosch

  • divar_ip_7000
  • divar_ip_7000_r3
  • video_management_system_viewer
  • divar_ip_7000_firmware
  • divar_ip_3000_firmware
  • divar_ip_6000_firmware
  • video_management_system
  • divar_ip_6000
  • divar_ip_4000_firmware
  • divar_ip_5000
  • divar_ip_5000_firmware
  • divar_ip_4000
  • divar_ip_7000_r3_firmware
  • divar_ip_7000_r2_firmware
  • divar_ip_3000
  • divar_ip_7000_r2
CWE
CWE-863

Incorrect Authorization

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor