IQSIGHT Security Advisories - PSIRT (Product Security Incident Response Team)

This article provides an overview of all published Security Advisories related to our products and services.

The official Security Advisories are published on the following page: IQSIGHT Security Advisories

2026

Advisory number

Title

Affected Products

Summary

IQSIGHT-SI-2026-0601

Publication
Date:

2026-06-01

Microsoft 2011 Secure Boot Certificate Expiration

  • DIVAR IP all-in-one 6000 (DIP-64xx)

  • DIVAR IP all-in-one 4000 (DIP-44xx)

Microsoft is replacing its 2011-era Secure Boot certificates, which begin expiring in June 2026, with a new 2023 certificate set (Microsoft Corporation KEK CA 2023, Windows UEFI CA 2023, Microsoft UEFI CA 2023, and Microsoft Option ROM UEFI CA 2023). The 2023 certificates extend the Secure Boot chain of trust on Windowsbased devices. Affected IQSIGHT appliances will continue to start and operate normally after the 2011 certificates expire, and standard Windows updates will continue to install. However, devices that do not receive the 2023 certificates will no longer be able to apply new early-boot security updates, including updates to the Windows Boot Manager, Secure Boot databases (DB/DBX), and revocations for newly discovered boot-level vulnerabilities. Over time, this reduces protection against emerging boot-level threats but does not affect day-to-day functionality.

IQSIGHT-SI-2026-0528

Publication
Date: 
2026-05-28

Microsoft Defender SmartScreen Warning on BVMS 14.0

  • DIVAR IP all-in-one 5000 (DIP-52xx) All models

  • DIVAR IP all-in-one 7000 (DIP-72xx) All models

  • DIVAR IP all-in-one 7000 R3 (DIP-73xx) All models

  • DIVAR IP all-in-one 7000 (DIP-74xx) All models

  • DIVAR IP all-in-one 4000 (DIP-44xx) All models

  • DIVAR IP all-in-one 6000 (DIP-64xx) All models

  • BVMS 14.

 

When installing or running BVMS 14.0, some users may encounter a Microsoft Defender SmartScreen warning dialog stating that the application is “unrecognized” or that “Windows protected your PC.” The warning identifies the publisher as “IQSIGHT B.V.” and appears because this publisher has not yet accumulated sufficient download-based reputation in Microsoft Defender Threat Intelligence database for BVMS 14.0.

2025

Advisory number

Title

Affected Products

Summary

KSA-254356

Publication
Date:

2025-08-27 

BVMS Unrestricted SSH Resource Consumption

  • BVMS

  • DIVAR IP all-in-one 4000

  • DIVAR IP all-in-one 5000

  • DIVAR IP all-in-one 6000

  • DIVAR IP all-in-one 7000

BVMS SSH Server, while providing secure remote access, can be susceptible to resource consumption issues that can impact server performance and potentially lead to denial-of-service conditions. The service may become unresponsive or crash due to resource exhaustion, denying service to legitimate users. Affected BVMS versions start from 7.5 and include all versions up to and including 12.3.

BOSCH-SA-904062-BT

Publication




Date: 




2025-01-15

Unquoted Service Path Enumeration on SMCWatchDog Agent

  • Bosch DIVAR IP all-in-one 7000 (DIP-72xx)

 

An unquoted service path enumeration vulnerability on SMCWatchDog agent has been found affecting the DIVAR IP all-in-one 7000 (DIP-72xx) devices. This vulnerability can allow a local attacker to gain elevated privileges.

*CVSS - Common Vulnerability Scoring System

2024

Click to expand...

Advisory number

Title

Affected Products

Summary

BOSCH-SA-162032-BT

Publication
Date: 
2024-10-16

Unrestricted resource consumption in BVMS

  • Bosch BVMS

  • Bosch BVMS Viewer

  • Bosch Bosch DIVAR IP 7000 R2

  • Bosch Bosch DIVAR IP all-in-one 5000

  • Bosch Bosch DIVAR IP all-in-one 7000

  • Bosch Bosch DIVAR IP all-in-one 7000 R3

  • Bosch DIVAR IP all-in-one 4000

  • Bosch DIVAR IP all-in-one 6000

 

A vulnerability has been identified in the Bosch VMS Central Server concerning unrestricted resource consumption, leading to excessive use of disk space. The uncontrolled resource consumption can lead to a significant impact on the availability and performance of the affected system. This can result in the inability to store new data, process incoming requests, and perform essential system functions. In severe cases, it may lead to system crashes and data loss.

BOSCH-SA-981803-BT

Publication
Date: 
2024-10-01

Sensitive information disclosure in Bosch Configuration Manager

Bosch Bosch Configuration Manager


A vulnerability was discovered during internal testing of the Bosch Configuration Manager, which may temporarily store sensitive information of the configured system.

BOSCH-SA-659648-BT

Publication
Date: 
2024-08-21

Unauthenticated information leak in Bosch IP cameras

Bosch Camera Firmware

A vulnerability was discovered in internal testing of Bosch IP cameras of families CPP13 and CPP14, that allows an unauthenticated attacker to retrieve video analytics event data. No video data is leaked through this vulnerability.

BOSCH-SA-587194-BT

Publication
Date: 
2024-08-07

Multiple Curl vulnerabilities in the Git for Windows component of Bosch DIVAR IP all-in-one Devices

  • Bosch DIVAR IP all-in-one 4000 (DIP-44xx)

  • Bosch DIVAR IP all-in-one 6000 (DIP-64xx)

  • Bosch DIVAR IP all-in-one 7000 (DIP-74xx)

  • Bosch DIVAR IP all-in-one 7000 R3 (DIP-73xx)

  • Bosch DIVAR IP all-in-one 7000 (DIP-72xx)

  • Bosch DIVAR IP all-in-one 5000 (DIP-52xx)

DIVAR IP System Manager is a central user interface that provides an easy system setup, configuration and application software upgrades through an easily accessible web-based application.


Multiple Curl vulnerabilities in the Git for Windows component have been discovered in DIVAR IP System Manager versions prior to 2.3.2, affecting several Bosch DIVAR IP all-in-one models.

BOSCH-SA-246962-BT

Publication
Date: 
2024-03-13

BVMS affected by Autodesk Design Review Multiple Vulnerabilities

  • Bosch BVMS

  • Bosch BVMS Viewer

  • Bosch Bosch DIVAR IP 7000 R2

  • Bosch Bosch DIVAR IP all-in-one 5000

  • Bosch Bosch DIVAR IP all-in-one 7000

  • Bosch Bosch DIVAR IP all-in-one 7000 R3

BVMS was using Autodesk Design Review for showing 2D/3D files. Autodesk has published multiple vulnerabilities which when successfully exploited could lead to the execution of arbitrary code.

Starting from BVMS version 11.0, the Autodesk Design Review is not used anymore in BVMS, but the BVMS setup does not uninstall the Autodesk Design Review during a BVMS upgrade. This means only BVMS systems are affected which have versions <= 10.1.1.12 or were upgraded from BVMS Version <= 10.1.1.12 to a higher version.

  • Bosch does not provide any patches for BVMS <= 10.1.1.12

  • For BVMS systems upgraded from any BVMS version <= 10.1.1.12 Bosch advises to mitigate the vulnerability.

  • Fresh BVMS installations starting from BVMS 11.0 are not affected

Before removing Autodesk Design Review v 9.1.0.127 make sure that it is not used by any other software installed on that machine.

How to check if the system is affected:

  1. In the Search bar, search for "add remove" and select "Add remove programs".

  2. Check whether Autodesk Design Review v 9.1.0.127 is installed.

BOSCH-SA-090577-BT

Publication
Date: 
2024-03-06

Multiple OpenSSL vulnerabilities in BVMS

  • Bosch BVMS

  • Bosch BVMS Viewer

  • Bosch DIVAR IP 7000 R2

  • Bosch DIVAR IP all-in-one 5000

  • Bosch DIVAR IP all-in-one 7000

  • Bosch DIVAR IP all-in-one 7000 R3

  • Bosch DIVAR IP all-in-one 4000

  • Bosch DIVAR IP all-in-one 6000

BVMS is using a Device Adapter service for communication with Tattile cameras which is also active when no Tattile cameras are added in the BVMS installation. This service uses an OpenSSL library, which has multiple vulnerabilities as published by OpenSSL. When successfully exploited, these vulnerabilities could lead to command injection or denial of service.

BOSCH-SA-637386-BT

Publication
Date: 
2024-03-06

Git for Windows Multiple Security Vulnerabilities in Bosch DIVAR IP all-in-one Devices

  • Bosch Bosch DIVAR IP all-in-one 4000 (DIP-44xx)

  • Bosch Bosch DIVAR IP all-in-one 5000 (DIP-52xx)

  • Bosch Bosch DIVAR IP all-in-one 6000 (DIP-64xx)

  • Bosch Bosch DIVAR IP all-in-one 7000 (DIP-72xx)

  • Bosch Bosch DIVAR IP all-in-one 7000 R3 (DIP-73xx)

DIVAR IP System Manager is a central user interface that provides an easy system setup, configuration and application software upgrades through an easily accessible web-based application.
Multiple Git for Windows vulnerabilities have been discovered in DIVAR IP System Manager versions prior to 2.3.0, affecting several Bosch DIVAR IP all-in-one models.

2023

Click to expand...

Advisory number

Title

Affected Products

Summary

BOSCH-SA-638184-BT


Command injection vulnerability in Bosch IP Cameras

  • Bosch Camera Firmware

A vulnerability was discovered in Bosch IP cameras of families CPP13 and CPP14, that allows an authenticated user with administrative rights to execute arbitrary commands in the operating system of the camera.

BOSCH-SA-092656-BT


Denial of Service vulnerability in Bosch BT software products

  • Bosch BIS Video Engine

  • Bosch BVMS

  • Bosch BVMS Viewer

  • Bosch Configuration Manager

  • Bosch DIVAR IP 7000 R2

  • Bosch DIVAR IP all-in-one 4000

  • Bosch DIVAR IP all-in-one 5000

  • Bosch DIVAR IP all-in-one 6000

  • Bosch DIVAR IP all-in-one 7000

  • Bosch DIVAR IP all-in-one 7000 R3

  • Bosch Intelligent Insights

  • Bosch Monitorwall

  • Bosch ONVIF Camera Event Driver Tool

  • Bosch Project Assistant

  • Bosch VJD-7513

  • Bosch VJD-7523

  • Bosch Video Recording Manager

  • Bosch Video Security Client

  • Bosch Video Streaming Gateway

An security vulnerability discovered in Bosch internal tests allows an unauthenticated attacker to interrupt normal functions and cause a Denial of Service / DoS.

Bosch rates this vulnerability with a CVSSv3.1 base scores of 7.5 (High) for products using the vulnerable function as a server and 5.9 (medium) for products using the vulnerable function as a client, where the actual rating depends on the individual vulnerability and the final rating on the customer’s environment.

Customers are strongly advised to update to the fixed versions.

BOSCH-SA-839739-BT




Information Disclosure Vulnerability in Bosch IP cameras



• Bosch Camera Firmware




An information disclosure vulnerability was discovered in Bosch IP camera devices allowing an unauthenticated attacker to retrieve information about the device itself (like capabilities) and network settings of the device, disclosing possibly internal network settings if the device is connected to the internet.

This vulnerability was discovered by Souvik Kandar and Arko Dhar from Redinent Innovations, India

BOSCH-SA-435698-BT


Possible damage of secure element in Bosch IP cameras


• Bosch Camera Firmware



Due to an error in the software interface to the secure element chip on the cameras, the chip can be permanently damaged leading to an unusable camera when enabling the Stream security option (signing of the video stream) on Bosch CPP13 and CPP14 cameras. The default setting for this option is "off".

BOSCH-SA-110112-BT









.NET Remote Code Execution Vulnerability in BVMS, BIS and AMS








• Bosch AMS
• Bosch BIS
• Bosch BVMS
• Bosch BVMS Viewer
• Bosch DIVAR IP 7000 R2
• Bosch DIVAR IP all-in-one 5000
• Bosch DIVAR • IP all-in-one 7000
• Bosch DIVAR IP all-in-one 7000 R3
• Bosch DIVAR IP all-in-one 4000
• Bosch DIVAR IP all-in-one 6000

The Bosch Video Management System (BVMS), the Bosch Access Management System (AMS), and the Bosch Building Integration System (BIS) are using a vulnerable version of the Microsoft .NET package System.Text.Encodings.Web.

The System.Text.Encodings.Web is a NuGet package from Microsoft, and Microsoft has published an advisory to provide information about a vulnerability in System.Text.Encodings.Web.

A remote code execution vulnerability exists in System.Text.Encodings.Web due to how text encoding is performed.



BOSCH-SA-025794-BT









Unrestricted SSH port forwarding in BVMS










• Bosch BVMS
• Bosch BVMS Viewer
• Bosch DIVAR IP 3000
• Bosch DIVAR IP 7000 R1
• Bosch DIVAR IP 7000 R2
• Bosch DIVAR IP all-in-one 5000
• Bosch DIVAR IP all-in-one 7000
• Bosch DIVAR IP all-in-one 7000 R3
• Bosch DIVAR IP all-in-one 4000
• Bosch DIVAR IP all-in-one 6000

The Bosch Video Management System is using SSH server that does not restrict a port forwarding requested by an authenticated SSH client. An authenticated SSH client can request a connection which is forwarded by the BVMS SSH server to a resource within the trusted internal network, which is normally protected from the WAN interface. The resource can be beyond the scope of the Bosch Video Management System.




info