Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-11684

31
FAUCET Score

CVE-2019-11684 is a critical improper access control vulnerability in the RCP+ server of Bosch Video Recording Manager (VRM) and related products, including DIVAR IP 5000 and BVMS. It allows unauthenticated attackers to access a limited subset of certificates stored on the underlying Windows OS. With a CVSS score of 9.8 (Critical), this vulnerability poses a high risk due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered significant community discussion, indicating awareness and potential for future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.70, < 3.71.0034CPE matchmatch criteria
cpe:2.3:a:bosch:video_recording_manager:*:*:*:*:*:*:*:*
>= 3.81, < 3.81.0050CPE matchmatch criteria
cpe:2.3:a:bosch:video_recording_manager:*:*:*:*:*:*:*:*
>= 3.80, < 3.80.0039CPE matchmatch criteria
cpe:2.3:o:bosch:divar_ip_5000_firmware:*:*:*:*:*:*:*:*
3.70.0056CPE matchmatch criteria
cpe:2.3:a:bosch:video_management_system:3.70.0056:*:*:*:*:*:*:*
3.70.0058CPE matchmatch criteria
cpe:2.3:a:bosch:video_management_system:3.70.0058:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.9CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
5.3
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.99%
Probability of exploitation in next 30 days
EPSS Percentile
58.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0099 is in the 44th percentile among its peer group of 36,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (7)

autodeskvendor investigatingvia llm_extracted
clastixvendor investigatingvia llm_extracted
delta_electronicsvendor investigatingvia llm_extracted
dogukanurkervendor investigatingvia llm_extracted
View patch
eximvendor investigatingvia llm_extracted
View patch
langflowvendor investigatingvia llm_extracted
mediatekvendor investigatingvia llm_extracted

Vendor Advisories (7)

delta_electronicsllm-delta_electronics-c495c2f6b6c826d6CRITICAL

Unauthenticated Certificate Access in Video Recording Manager

May 9, 2019
autodeskllm-autodesk-4b813133000e3704CRITICAL

Unauthenticated Certificate Access in Video Recording Manager

May 9, 2019
dogukanurkerllm-dogukanurker-e14ae069cb2f3d56CRITICAL

Unauthenticated Certificate Access in Video Recording Manager

May 9, 2019
langflowllm-langflow-d9d116a7cdf4a94cCRITICAL

Unauthenticated Certificate Access in Video Recording Manager

May 9, 2019
eximllm-exim-88627b37d72f14e7CRITICAL

Unauthenticated Certificate Access in Video Recording Manager

May 9, 2019
clastixllm-clastix-a674b3b96f9ea2ffCRITICAL

Unauthenticated Certificate Access in Video Recording Manager

May 9, 2019
mediatekllm-mediatek-107ef16075a50e43CRITICAL

Unauthenticated Certificate Access in Video Recording Manager

May 9, 2019

References

psirt.bosch.com / security-advisories/bosch-sa-804652.html
Vendor Advisory