CVE-2021-23847
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD
Description
A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or change settings of the camera by sending crafted requests to the device. Only devices of the CPP6, CPP7 and CPP7.3 family with firmware 7.70, 7.72, and 7.80 prior to B128 are affected by this vulnerability. Versions 7.62 or lower and INTEOX cameras are not affected.
Affected (9)
Products: Bosch: Cpp6 Firmware, Cpp7 Firmware, Cpp7.3 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.80 to 7.80.0129 |
| Running on/with | Platform Versions |
|---|---|
Bosch Cpp6 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.80 to 7.80.0129 |
| Running on/with | Platform Versions |
|---|---|
Bosch Cpp7 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.80 to 7.80.0129 |
| Running on/with | Platform Versions |
|---|---|
Bosch Cpp7.3 | All versions |
Related CWEs
CWE-287
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-306
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
References (2)
Source: psirt@bosch.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.