← Back

CVE-2021-23859

nvd nist
Published: Dec 8, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM installation this crash also opens the possibility to send further unauthenticated commands to the service. On some products the interface is only local accessible lowering the CVSS base score. For a list of modified CVSS scores, please see the official Bosch Advisory Appendix chapter Modified CVSS Scores for CVE-2021-23859

Affected (12)

6 products
Bosch Video Management System
Video Recording Manager
Access Easy Controller Firmware
Access Professional Edition
Building Integration System
Video Recording Manager Exporter
Configuration A
8 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Bosch
Up to 9.0
From 10.0 to 10.0.2
Version 10.1
Version 11.0
Bosch
Up to 3.81
From 3.82 to 3.82.0057
From 3.83 to 3.83.0021
From 4.0 to 4.00.0070
Running on/withPlatform Versions
Bosch
Divar Ip 5000 Firmware
All versions
Bosch
Divar Ip 7000 Firmware
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.9.1.0
Running on/withPlatform Versions
Bosch
Access Easy Controller
All versions
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.8.0
Up to 4.9
From 2.1 to 2.10.0008

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.