CVE-2022-32540

MEDIUM

Bosch Video Management System 10.1-10.1.1, 11.0-11.1.0 & VIDEOJET Decoder VJD-7513 10.23-10.30 - UDP Info Disclosure

Title source: llm
STIX 2.1

Description

Information Disclosure in Operator Client application in BVMS 10.1.1, 11.0 and 11.1.0 and VIDEOJET Decoder VJD-7513 versions 10.23 and 10.30 allows man-in-the-middle attacker to compromise confidential video stream. This is only applicable for UDP encryption when target system contains cameras with platform CPP13 or CPP14 and firmware version 8.x.

References (1)

Core 1
Core References

Scores

CVSS v3 5.9
EPSS 0.0030
EPSS Percentile 21.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-200
Status published
Products (4)
bosch/bosch_video_management_system 11.0
bosch/bosch_video_management_system 10.1 - 10.1.1
bosch/videojet_decoder_7513_firmware 10.23.0002
bosch/videojet_decoder_7513_firmware 10.30.0005
Published Sep 30, 2022
Tracked Since Feb 18, 2026