9.8

CVE-2021-23847

A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or change settings of the camera by sending crafted requests to the device. Only devices of the CPP6, CPP7 and CPP7.3 family with firmware 7.70, 7.72, and 7.80 prior to B128 are affected by this vulnerability. Versions 7.62 or lower and INTEOX cameras are not affected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BoschCpp6 Firmware Version >= 7.80 < 7.80.0129
   BoschCpp6 Version-
BoschCpp6 Firmware Version7.70
   BoschCpp6 Version-
BoschCpp6 Firmware Version7.72
   BoschCpp6 Version-
BoschCpp7 Firmware Version >= 7.80 < 7.80.0129
   BoschCpp7 Version-
BoschCpp7 Firmware Version7.70
   BoschCpp7 Version-
BoschCpp7 Firmware Version7.72
   BoschCpp7 Version-
BoschCpp7.3 Firmware Version >= 7.80 < 7.80.0129
   BoschCpp7.3 Version-
BoschCpp7.3 Firmware Version7.70
   BoschCpp7.3 Version-
BoschCpp7.3 Firmware Version7.72
   BoschCpp7.3 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.634
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
psirt@bosch.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.