Bosch IP Camera Vulnerability (CVE-2018-19036)

fenderman

Staff member
Joined
Mar 9, 2014
Messages
36,903
Reaction score
21,275
Bosch IP Camera Vulnerability (CVE-2018-19036)
"Summary
A recently discovered security vulnerability affects several Bosch IP cameras. It potentially allows the unauthorized execution of code on the device via the network interface. Bosch rates this vulnerability at 9.4 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H, Critical) and recommends customers to upgrade devices with updated firmware versions.

As of 2018-12-11, updated firmware files are published on the Bosch Download Store (link). As of 2018-12-12, there is currently no indication that the exploitation code is either publicly known or utilized.

If a firmware update is not possible in a timely manner, a reduction in the devices’ network exposure is advised. Internet-accessible Bosch IP cameras should be firewalled, whilst additional steps like network isolation by VLAN, IP filtering features of the devices and other technologies should be used to decrease the exposure of vulnerable devices."
 

tangent

IPCT Contributor
Joined
May 12, 2016
Messages
4,426
Reaction score
3,666
Brands like Bosch aren't necessarily any more secure, but they certainly handle disclosure and software updates better then their Chinese brethren.
 

fenderman

Staff member
Joined
Mar 9, 2014
Messages
36,903
Reaction score
21,275
Brands like Bosch aren't necessarily any more secure, but they certainly handle disclosure and software updates better then their Chinese brethren.
This is the first vulnerability I have seen from Bosch. Unlike the monthly hik/dahua
 

c hris527

Known around here
Joined
Oct 12, 2015
Messages
1,795
Reaction score
2,094
Location
NY
You will not see too much Bosch with the Small Biz DYI people but I did have to work with a local Guy on the network end of it and he was brought in because the Installers who put in the system got banned from the campus and there was major issues with the system, I will say the support from Bosch was first class and they really went out of the way to support the product. I was in the room on speaker with Bosch and the " New System Integrator" as a network consultant to make sure it was not on the Facilities end. It took all of about of 15 mins to resolve the issue, They ended up with a firmware update to cure it or re-flashed it..not sure but seems it all good after that. At the time as far as I could see all the cams were 720p ip cams..I think they got ripped off myself, the only reason I know it was they kept some spare cams and a few empty boxes the the room I was working in from the Install.
 
Top