Robert Bosch GmbH's vulnerability portfolio spans a large collection of industrial automation and cordless tool products, including the Nexo operating system and a range of cordless nutrunner devices widely used in manufacturing and assembly environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity; however, the exposure reflects the embedded and operational-technology context of these products rather than trends toward public exploitation. The recurring weakness classes—including cross-site scripting, improper access control, path traversal, and uncontrolled search path elements—center on web-interface and file-access handling within industrial control and embedded firmware, areas where legacy design patterns and limited patch-deployment cycles compound the risk. Defenders managing Bosch industrial devices should prioritize inventory and network segmentation; live severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Robert Bosch GmbH over time
Of all the CVEs published by Robert Bosch GmbH as a CNA, 73.4% affect products that Robert Bosch GmbH develops as a vendor.
Of all the CVEs published that affect products developed by Robert Bosch GmbH, 87.0% are self-published by Robert Bosch GmbH as a CNA.
Signals from CVEs in this vendor scope (108 CVEs).
108 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-6770CRITICAL Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on the system. This affects Bosch | Feb 7, 2020 | 9.8 | 32 | NO | NO |
CVE-2019-11684CRITICAL Improper Access Control in the RCP+ server of the Bosch Video Recording Manager (VRM) component allows arbitrary and unauthenticated access to a limited subset of certificates, sto | Feb 26, 2021 | 9.8 | 31 | NO | NO |
CVE-2019-11898CRITICAL Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The service tool is discontinued with Bosch Access Professional Edit | Sep 12, 2019 | 9.9 | 31 | NO | NO |
CVE-2023-48266CRITICAL The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network reque | Jan 10, 2024 | 9.8 | 30 | NO | NO |
CVE-2021-23853CRITICAL In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP headers through crafted URLs. | Jun 9, 2021 | 9.8 | 30 | NO | NO |
CVE-2018-19036CRITICAL An issue was discovered in several Bosch IP cameras for firmware versions 6.32 and higher. A malicious client could potentially succeed in the unauthorized execution of code on the | Dec 17, 2018 | 9.8 | 30 | NO | NO |
CVE-2022-32534CRITICAL The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command injection through its diagnostics web interface. This allows ex | Jun 23, 2022 | 9.8 | 29 | NO | NO |
CVE-2021-23857CRITICAL Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this al | Oct 4, 2021 | 9.8 | 29 | NO | NO |
CVE-2018-20299CRITICAL An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firmware before 6.52.4. A malicious client could potentially suc | Dec 19, 2018 | 9.8 | 29 | NO | NO |
CVE-2023-48250CRITICAL The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded accounts. | Jan 10, 2024 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (108 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Robert Bosch GmbH.
Media articles that mention a CVE ID that affects a product developed by Robert Bosch GmbH — matched by CVE ID, not by vendor name.