CVE-2020-6788 is a high-severity vulnerability affecting the Bosch Configuration Manager installer up to version 7.21.0078. It allows for arbitrary code execution due to an uncontrolled search path element, where a malicious DLL placed in the installer's directory can be loaded. The attack requires user interaction (UI:R) to trick the victim into placing the DLL, but once executed, it grants high confidentiality, integrity, and availability impact (C:H/I:H/A:H). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.21.0078CPE matchmatch criteria | cpe:2.3:a:bosch:configuration_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Uncontrolled Search Path Element in Multiple Bosch Products
Mar 24, 2021Uncontrolled Search Path Element in Multiple Bosch Products
Mar 24, 2021Uncontrolled Search Path Element in Multiple Bosch Products
Mar 24, 2021Uncontrolled Search Path Element in Multiple Bosch Products
Mar 24, 2021Uncontrolled Search Path Element in Multiple Bosch Products
Mar 24, 2021Uncontrolled Search Path Element in Multiple Bosch Products
Mar 24, 2021