{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-29T15:44:27.351","vulnerabilities":[{"cve":{"id":"CVE-2019-8952","sourceIdentifier":"cve@mitre.org","published":"2019-05-13T22:29:01.153","lastModified":"2026-06-17T02:42:50.503","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A Path Traversal vulnerability located in the webserver affects several Bosch hardware and software products. The vulnerability potentially allows a remote authorized user to access arbitrary files on the system via the network interface. Affected hardware products: Bosch DIVAR IP 2000 (vulnerable versions: 3.10; 3.20; 3.21; 3.50; 3.51; 3.55; 3.60; 3.61; 3.62; fixed versions: 3.62.0019 and newer), Bosch DIVAR IP 5000 (vulnerable versions: 3.10; 3.20; 3.21; 3.50; 3.51; 3.55; 3.60; 3.61; 3.62; fixed versions: 3.80.0033 and newer). Affected software products: Video Recording Manager (VRM) (vulnerable versions: 3.10; 3.20; 3.21; 3.50; 3.51; 3.55; 3.60; 3.61; 3.62; 3.70; 3.71 before 3.71.0032 ; fixed versions: 3.71.0032; 3.81.0032 and newer), Bosch Video Management System (BVMS) (vulnerable versions: 3.50.00XX; 3.55.00XX; 3.60.00XX; 3.70.0056; fixed versions: 7.5; 3.71.0032)."},{"lang":"es","value":"Una vulnerabilidad de salto de directorio ubicada en el servidor web afecta a varios productos de hardware y software de Bosch. La vulnerabilidad permite potencialmente a un usuario remoto autorizado acceder a archivos arbitrarios en el sistema a través de la interfaz de red. Productos de hardware afectados: Bosch DIVAR IP 2000 (versiones vulnerables: 3.10; 3.20; 3.21; 3.50; 3.51; 3.55; 3.60; 3.61; 3.62; versiones que contienen la solución: 3.62.0019 y posteriores), Bosch DIVAR IP 5000 (versiones vulnerables: 3.10; 3.20; 3.21; 3.50; 3.51; 3.55; 3.60; 3.61; 3.62; versiones que contienen la solución: 3.80.0033 y posteriores). Productos de software afectados: Video Recording Manager (VRM) (versiones vulnerables: 3.10; 3.20; 3.21; 3.50; 3.51; 3.55; 3.60; 3.61; 3.62; 3.70; 3.71 antes de 3.71.0032 ; versiones que contienen la solución: 3.71.0032; 3.81.0032 y posteriores), Bosch Video Management System (BVMS) (versiones vulnerables: 3.50.00XX; 3.55.00XX; 3.60.00XX; 3.70.0056; versiones que contienen la solución: 7.5; 3.71.0032)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:bosch:divar_ip_2000_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"3.62.0019","matchCriteriaId":"360F7882-2D5C-46ED-A9C6-5A79129C272A"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:bosch:divar_ip_2000:-:*:*:*:*:*:*:*","matchCriteriaId":"114BF1E1-4E81-42C3-A563-7C4A523312A4"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:bosch:divar_ip_5000_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"3.80.0033","matchCriteriaId":"03229722-C77A-4B16-A90C-E9BA73F4A821"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:bosch:divar_ip_5000:-:*:*:*:*:*:*:*","matchCriteriaId":"AB0DE1C9-D3C0-49BF-9FFD-B765F9AF6691"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:bosch:video_management_system:*:*:*:*:*:*:*:*","versionEndExcluding":"3.71.0032","matchCriteriaId":"640B6AE6-691F-4C75-BD99-254D078D3080"},{"vulnerable":true,"criteria":"cpe:2.3:a:bosch:video_recording_manager:*:*:*:*:*:*:*:*","versionEndExcluding":"3.71.0032","matchCriteriaId":"526B56A8-3106-44C1-8C77-B22995A98C86"},{"vulnerable":true,"criteria":"cpe:2.3:a:bosch:video_recording_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"3.81","versionEndExcluding":"3.81.0032","matchCriteriaId":"DD1FA491-AF37-4C00-A6D6-DFA48DEF426D"}]}]}],"references":[{"url":"https://media.boschsecurity.com/fs/media/pb/security_advisories/bosch-2019-0402bt-cve-2019-8952_security_advisory_vrm_path_traversal.pdf","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://psirt.bosch.com","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://psirt.bosch.com/Advisory/BOSCH-2019-0402.html","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://www.boschsecurity.com/xc/en/support/product-security/security-advisories.html","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://media.boschsecurity.com/fs/media/pb/security_advisories/bosch-2019-0402bt-cve-2019-8952_security_advisory_vrm_path_traversal.pdf","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://psirt.bosch.com","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://psirt.bosch.com/Advisory/BOSCH-2019-0402.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://www.boschsecurity.com/xc/en/support/product-security/security-advisories.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}