CVE-2023-32229
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
Due to an error in the software interface to the secure element chip on Bosch IP cameras of family CPP13 and CPP14, the chip can be permanently damaged when enabling the Stream security option (signing of the video stream) with option MD5, SHA-1 or SHA-256.
Affected (2)
Products: Bosch: Cpp13 Firmware, Cpp14 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.48.0017 |
| Running on/with | Platform Versions |
|---|---|
Bosch Autodome 7000i | All versions |
Bosch Autodome 7100 Ir | All versions |
Bosch Autodome Inteox 7000i | All versions |
Bosch Dinion Inteox 7100i Ir | All versions |
Bosch Flexidome Inteox 7100i Ir | All versions |
Bosch Mic Inteox 7100i | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 8.50 to 8.80.0090 |
| Running on/with | Platform Versions |
|---|---|
Bosch Dinion 7100i Ir | All versions |
Bosch Flexidome Indoor 5100i | All versions |
Bosch Flexidome Indoor 5100i Ir | All versions |
Bosch Flexidome Multi 7000i | All versions |
Bosch Flexidome Multi 7000i Ir | All versions |
Bosch Flexidome Outdoor 5100i | All versions |
Bosch Flexidome Outdoor 5100i Ir | All versions |
Bosch Flexidome Panoramic 5100i | All versions |
Bosch Flexidome Panoramic 5100i Ir | All versions |
Related CWEs
CWE-1246
Improper Write Handling in Limited-write Non-Volatile Memories
The product does not implement or incorrectly implements wear leveling operations in limited-write non-volatile memories.
CWE-400
Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
References (2)
Source: psirt@bosch.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.