Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2020-6776 Details

Description

A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAESENSA until and including version 1.10 allows an unauthenticated remote attacker to trigger actions on an affected system on behalf of another user (Cross-Site Request Forgery). This requires the victim to be tricked into clicking a malicious link or submitting a malicious form. A successful exploit allows the attacker to perform arbitrary actions with the privileges of the victim, e.g. creating and modifying user accounts, changing system configuration settings and cause DoS conditions. Note: For Bosch PRAESIDEO 4.31 and newer and Bosch PRAESENSA in all versions, the confidentiality impact is considered low because user credentials are not shown in the web interface.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-352Cross-Site Request Forgery (CSRF)[email protected]
CWE-352Cross-Site Request Forgery (CSRF)[email protected]

Affected Products

ProductVersions
bosch praesideo firmware
<= 4.41

CPE

  • cpe:2.3:o:bosch:praesideo_firmware:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
bosch praesideo
All versions

CPE

  • cpe:2.3:h:bosch:praesideo:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
bosch praesensa firmware
<= 1.10

CPE

  • cpe:2.3:o:bosch:praesensa_firmware:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
bosch praesensa
All versions

CPE

  • cpe:2.3:h:bosch:praesensa:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2020-6776
NVD Published Date:
Jan 14, 2021
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2020-6776 Details - Not Deferred