CVE-2023-28175: Bosch Divar IP 3000 Firmware
High severity, CVSS 7.7. EPSS: 0.5% chance of exploitation in the next 30 days.
Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access resources within the trusted internal network via a port forwarding request.
Affected products
- Bosch Divar IP 3000 Firmware: from 7.5, up to and including 8.0
- Bosch Divar IP 4000 Firmware: version 11.1.1 only
- Bosch Divar IP 5000 Firmware: from 9.0, up to and including 11.1.1
- Bosch Divar IP 6000 Firmware: version 11.1.1 only
- Bosch Divar IP 7000 Firmware: from 7.5, up to and including 8.0
- Bosch Divar IP 7000 r2 Firmware: from 7.5, up to and including 11.1.1
- Bosch Divar IP 7000 r3 Firmware: from 10.1.1, up to and including 11.1.1
- Bosch Video Management System: from 7.5, up to and including 11.1.1
- Bosch Video Management System Viewer: from 7.5, up to and including 11.1.1
Published 2023-06-15. Last modified 2026-06-17.