Robert Bosch GmbH

First CVE: May 29, 2019Active for: 7 years
128
CVEs Published
More CVEs Published than 73% of tracked CNAs
16.0
Avg CVEs / Year
More Avg CVEs / Year than 63% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 67% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Robert Bosch GmbH as a CNA, 73.4% affect products that Robert Bosch GmbH develops as a vendor.

73.4%
26.6%
Self-reported: 94Third-party: 34

Of all the CVEs published that affect products developed by Robert Bosch GmbH, 87.0% are self-published by Robert Bosch GmbH as a CNA.

87.0%
13.0%
Self-published: 94Published by other CNAs: 14

Trends Over Time

The number and severity of CVEs published by Robert Bosch GmbH over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 29, 2019
7 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs

All CVEs published by Robert Bosch GmbH as a CNA, regardless of affected vendor or product.

128 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.
Jul 23, 20268.434NONO
A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.
Jul 23, 20267.532NONO
Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on the system. This affects Bosch
Feb 7, 20209.832NONO
Remote code execution that allows unauthorized users to execute arbitrary code on the server machine.
Jun 13, 202510.031NONO
Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The service tool is discontinued with Bosch Access Professional Edit
Sep 12, 20199.931NONO
The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network reque
Jan 10, 20249.830NONO
In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP headers through crafted URLs.
Jun 9, 20219.830NONO
The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command injection through its diagnostics web interface. This allows ex
Jun 23, 20229.829NONO
Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this al
Oct 4, 20219.829NONO
The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded accounts.
Jan 10, 20249.828NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA128 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local16 (12.5%)
Network97 (75.8%)
Unknown0 (0.0%)
Physical2 (1.6%)
Adjacent Network13 (10.2%)
Attack Complexity
Low118 (92.2%)
High10 (7.8%)
Unknown0 (0.0%)
User Interaction
None92 (71.9%)
Unknown0 (0.0%)
Required36 (28.1%)
Privileges Required
Low37 (28.9%)
High10 (7.8%)
None81 (63.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (128 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Robert Bosch GmbH as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Robert Bosch GmbH as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs