---
cve: "CVE-2019-6958"
severity: "CRITICAL"
cvss: 9.8
epss: "1.5%"
vendor: "n/a"
kev: false
exploited: false
published: "2019-05-29 19:29:00"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-07T04:12:49+02:00"
---

# CVE-2019-6958

> 9.8 CRITICAL

## Beschreibung

A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Configuration Manager, Building Integration System (BIS) with Video Engine, Access Professional Edition (APE), Access Easy Controller (AEC), Bosch Video Client (BVC) and Video SDK (VSDK). The RCP+ network port allows access without authentication. Adding authentication feature to the respective library fixes the issue. The issue is classified as "CWE-284: Improper Access Control." This vulnerability, for example, allows a potential attacker to delete video or read video data.

## CVSS-Vektor

```
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Schwachstellen-Klasse

- **CWE-284** — Improper Access Control
  The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

## Angriffsmuster (CAPEC)

- [CAPEC-19 — Embedding Scripts within Scripts](https://capec.mitre.org/data/definitions/19.html) _(Severity: High)_
- [CAPEC-441 — Malicious Logic Insertion](https://capec.mitre.org/data/definitions/441.html) _(Severity: High)_
- [CAPEC-478 — Modification of Windows Service Configuration](https://capec.mitre.org/data/definitions/478.html) _(Severity: High)_
- [CAPEC-479 — Malicious Root Certificate](https://capec.mitre.org/data/definitions/479.html) _(Severity: Low)_
- [CAPEC-502 — Intent Spoof](https://capec.mitre.org/data/definitions/502.html)
- [CAPEC-503 — WebView Exposure](https://capec.mitre.org/data/definitions/503.html)
- [CAPEC-536 — Data Injected During Configuration](https://capec.mitre.org/data/definitions/536.html) _(Severity: High)_
- [CAPEC-546 — Incomplete Data Deletion in a Multi-Tenant Environment](https://capec.mitre.org/data/definitions/546.html) _(Severity: Medium)_

## ATT&CK-Techniken

- [T1027.009 — Obfuscated Files or Information: Embedded Payloads](https://attack.mitre.org/techniques/T1027/009/)
- [T1546.004 — Event Triggered Execution:.bash_profile and .bashrc](https://attack.mitre.org/techniques/T1546/004/)
- [T1546.016 — Event Triggered Execution: Installer Packages](https://attack.mitre.org/techniques/T1546/016/)
- [T1574.011 — Hijack Execution Flow:Service Registry Permissions Weakness](https://attack.mitre.org/techniques/T1574/011/)
- [T1543.003 — Create or Modify System Process:Windows Service](https://attack.mitre.org/techniques/T1543/003/)
- [T1553.004 — Subvert Trust Controls:Install Root Certificate](https://attack.mitre.org/techniques/T1553/004/)

## Referenzen

- <https://media.boschsecurity.com/fs/media/pb/security_advisories/bosch-2019-0404bt-cve-2019-6958_security_advisory_improper_access_control.pdf>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2019-6958) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
