CVE-2024-33618
7.5Bosch · VMS Central
A vulnerability in the Bosch VMS Central Server allows unauthenticated attackers to trigger uncontrolled resource consumption, potentially leading to a denial of service via excessive disk space usage.
Executive summary
An unauthenticated resource exhaustion vulnerability in Bosch VMS software poses a significant risk of service disruption for critical video management infrastructure.
Vulnerability
The flaw is an uncontrolled resource consumption issue (CWE-400) that can be triggered by an unauthenticated attacker over the network. By sending specially crafted requests, an attacker can force the system to consume excessive disk space, resulting in a denial of service.
Business impact
Successful exploitation results in the exhaustion of storage resources, which can render the VMS system inoperable. Given the CVSS score of 7.5, this high-severity flaw threatens the availability of physical security monitoring systems, potentially leading to significant operational downtime and loss of surveillance capabilities.
Remediation
Immediate Action: Review the official Bosch security advisory (BOSCH-SA-162032-BT) to identify available patches or configuration workarounds for your specific hardware and software version.
Proactive Monitoring: Monitor disk utilization levels on VMS servers and establish alerts for abnormal growth in logs or temporary storage directories.
Compensating Controls: Implement network-level access controls to restrict access to the VMS management interface to authorized IP addresses only, reducing the attack surface for unauthenticated actors.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations utilizing affected Bosch VMS products must prioritize this vulnerability due to its potential to cause widespread system failure. Security teams should verify their current version against the affected list immediately and apply vendor-supplied updates or mitigations as soon as they become available to maintain system integrity.