CRITICAL · 9.8

CVE-2015-6970

The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to conduct XML injection attacks via the idstring parameter to r...

Vulnerability Description

The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to conduct XML injection attacks via the idstring parameter to rcp.xml.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
BoschsecurityNbn-498 Dinion2X Day\/Night Ip Cameras Firmware4.54.0026
BoschsecurityNbn-498 Dinion2X Day\/Night Ip Cameras-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-6970?

CVE-2015-6970 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to conduct XML injection attacks via the idstring parameter to r...

How severe is CVE-2015-6970?

CVE-2015-6970 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2015-6970?

Check the references section above for vendor advisories and patch information. Affected products include: Boschsecurity Nbn-498 Dinion2X Day\/Night Ip Cameras Firmware, Boschsecurity Nbn-498 Dinion2X Day\/Night Ip Cameras.