← Back

CVE-2021-23847

nvd nist
Published: Jun 9, 2021Modified: Jun 17, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or change settings of the camera by sending crafted requests to the device. Only devices of the CPP6, CPP7 and CPP7.3 family with firmware 7.70, 7.72, and 7.80 prior to B128 are affected by this vulnerability. Versions 7.62 or lower and INTEOX cameras are not affected.

Affected (9)

3 products
Cpp6 Firmware
Cpp7 Firmware
Cpp7.3 Firmware
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Bosch
From 7.80 to 7.80.0129
Version 7.70
Version 7.72
Running on/withPlatform Versions
Bosch
Cpp6
All versions
Configuration B
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Bosch
From 7.80 to 7.80.0129
Version 7.70
Version 7.72
Running on/withPlatform Versions
Bosch
Cpp7
All versions
Configuration C
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Bosch
From 7.80 to 7.80.0129
Version 7.70
Version 7.72
Running on/withPlatform Versions
Bosch
Cpp7.3
All versions

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.