CameraRisk

CVE-2019-11684

Bosch

Published
26 February 2021
Last modified
17 June 2026
CVSS
9.8 v3.1
Severity
critical
EPSS
1.0% (60th pct)
CISA KEV
Not listed
NVD status
Modified
Weaknesses
CWE-306

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Improper Access Control in the RCP+ server of the Bosch Video Recording Manager (VRM) component allows arbitrary and unauthenticated access to a limited subset of certificates, stored in the underlying Microsoft Windows operating system. The fixed versions implement modified authentication checks. Prior releases of VRM software version 3.70 are considered unaffected. This vulnerability affects VRM v3.70.x, v3.71 < v3.71.0034 and v3.81 < 3.81.0050; DIVAR IP 5000 3.80 < 3.80.0039; BVMS all versions using VRM.

Exploitation

Not listed in the CISA Known Exploited Vulnerabilities catalogue as of 2026.09.04. That is an absence of confirmed public exploitation, not evidence that exploitation has not occurred. EPSS models a 1.0% probability of exploitation activity in the next 30 days.

Affected products

ProductVendorTypeVersions named
Divar IP 5000 Bosch unknown < 3.80.0033, < 3.80.0039, <= 11.1.1, <= 3.80.0039 +2
Video Management System Bosch unknown 3.70.0056, 3.70.0058, 3.70.0060, 3.70.0062 +22
Video Recording Manager Bosch unknown < 3.70.0056, < 3.71.0032, < 3.71.0034, < 3.81.0032 +15

References

Vendor advisory and patch

CVE-2019-11684 at NVD

Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.