CVE-2026-10764
Received Received - Intake

Information Disclosure in BVMS Versions 4.5 to 12.3

Vulnerability report for CVE-2026-10764, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: 4237bc98-ed97-4aeb-8e67-37a47a9e179d

Description

Information disclosure in BVMS 4.5 up to 12.3 including allows man-in-the-middle attackers to gain unauthorized access to sensitive data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
iqsight bvms to 12.3 (inc)
iqsight divar_ip to 12.3 (inc)
iqsight divar_ip to 12.0.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-321 The product uses a hard-coded, unchangeable cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-10764 is a critical information disclosure vulnerability in IQSIGHT BVMS and DIVAR IP products. It involves hard-coded cryptographic keys (CWE-321) that allow man-in-the-middle attackers to intercept or manipulate sensitive data transmitted over secure channels, potentially leading to unauthorized access to confidential information.

Detection Guidance

Detection involves checking for outdated BVMS versions (4.5-12.3) or DIVAR IP firmware (up to 12.3/12.0.1) and verifying if the 'BVMS_SecurityUpdate_01' patch is installed. Inspect network traffic for unusual man-in-the-middle activity or unencrypted sensitive data transmission.

Impact Analysis

This vulnerability may allow attackers to bypass security measures and gain access to sensitive communications. It could lead to unauthorized access to confidential information, posing risks to data privacy and security for users of affected BVMS and DIVAR IP systems.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate GDPR's data protection requirements and HIPAA's safeguards for protected health information. Non-compliance risks include legal penalties, fines, and reputational damage due to potential data breaches.

Mitigation Strategies
  • Install the 'BVMS_SecurityUpdate_01' tool on all affected systems including BVMS servers, clients, and DIVAR IP devices.
  • Apply all Microsoft patches and updates to the system.
  • For BVMS 12.2 with OIDC enabled, install the cumulative patch 'BVMS1220296_Patch_Cum11.zip'.
  • Ensure .NET Framework 4.8 is installed before applying updates.
  • Restart BVMS services or the entire machine after installing updates.
  • Upgrade to BVMS version 13.0 or higher for a permanent solution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10764. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart