CVE-2020-6767: Bosch Video Management System

Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.

A path traversal vulnerability in the Bosch Video Management System (BVMS) FileTransferService allows an authenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5 and older. This affects Bosch BVMS Viewer versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5 and older. This affects Bosch DIVAR IP 3000, DIVAR IP 7000 and DIVAR IP all-in-one 5000 if a vulnerable BVMS version is installed.

Affected products

  • Bosch Video Management System: up to and including 7.5; from 8.0, up to and including 8.0.0.329; from 9.0, up to and including 9.0.0.827; from 10.0, up to and including 10.0.0.1225
  • Bosch Video Management System Viewer: up to and including 7.5; from 8.0, up to and including 8.0.329; from 9.0, up to and including 9.0.0.827; from 10.0, up to and including 10.0.0.1225

Published 2020-02-06. Last modified 2026-06-17.