← Back

CVE-2021-23862

nvd nist
Published: Dec 8, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in system context. This issue also affects installations of the VRM, DIVAR IP, BVMS with VRM installed, the VIDEOJET decoder (VJD-7513 and VJD-8000).

Affected (10)

4 products
Bosch Video Management System
Video Recording Manager
Videojet Decoder 7513 Firmware
Videojet Decoder 8000 Firmware
Configuration A
8 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Bosch
Up to 9.0
From 10.0 to 10.0.2
Version 10.1
Version 11.0
Bosch
Up to 3.81
From 3.82 to 3.82.0057
From 3.83 to 3.83.0021
From 4.0 to 4.00.0070
Running on/withPlatform Versions
Bosch
Divar Ip 5000 Firmware
All versions
Bosch
Divar Ip 7000 Firmware
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 10.22.0038
Running on/withPlatform Versions
Bosch
Videojet Decoder 7513
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 10.01.0036
Running on/withPlatform Versions
Bosch
Videojet Decoder 8000
All versions

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.