CRITICAL · 9.8

CVE-2018-20299

An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firmware before 6.52.4. A malicious client could potentially succeed in the unauthor...

Vulnerability Description

An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firmware before 6.52.4. A malicious client could potentially succeed in the unauthorized execution of code on the device via the network interface, because there is a buffer overflow in the RCP+ parser of the web server.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Bosch360-Indoor Camera Firmware< 6.52.4
Bosch360-Indoor Camera-
BoschEyes Outdoor Camera Firmware< 6.52.4
BoschEyes Outdoor Camera-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-20299?

CVE-2018-20299 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firmware before 6.52.4. A malicious client could potentially succeed in the unauthor...

How severe is CVE-2018-20299?

CVE-2018-20299 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2018-20299?

Check the references section above for vendor advisories and patch information. Affected products include: Bosch 360-Indoor Camera Firmware, Bosch 360-Indoor Camera, Bosch Eyes Outdoor Camera Firmware, Bosch Eyes Outdoor Camera.