CVE-2023-28175: Bosch Divar IP 3000 Firmware

High severity, CVSS 7.7. EPSS: 0.5% chance of exploitation in the next 30 days.

Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote authenticated user to access resources within the trusted internal network via a port forwarding request.

Affected products

  • Bosch Divar IP 3000 Firmware: from 7.5, up to and including 8.0
  • Bosch Divar IP 4000 Firmware: version 11.1.1 only
  • Bosch Divar IP 5000 Firmware: from 9.0, up to and including 11.1.1
  • Bosch Divar IP 6000 Firmware: version 11.1.1 only
  • Bosch Divar IP 7000 Firmware: from 7.5, up to and including 8.0
  • Bosch Divar IP 7000 r2 Firmware: from 7.5, up to and including 11.1.1
  • Bosch Divar IP 7000 r3 Firmware: from 10.1.1, up to and including 11.1.1
  • Bosch Video Management System: from 7.5, up to and including 11.1.1
  • Bosch Video Management System Viewer: from 7.5, up to and including 11.1.1

Published 2023-06-15. Last modified 2026-06-17.