8.8

CVE-2021-23849

A vulnerability in the web-based interface allows an unauthenticated remote attacker to trigger actions on an affected system on behalf of another user (CSRF - Cross Site Request Forgery). This requires the victim to be tricked into clicking a malicious link or opening a malicious website while being logged in into the camera.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BoschCpp4 Firmware Version7.10
   BoschCpp4 Version-
BoschCpp6 Firmware Version7.60
   BoschCpp6 Version-
BoschCpp6 Firmware Version7.61
   BoschCpp6 Version-
BoschCpp6 Firmware Version7.70
   BoschCpp6 Version-
BoschCpp6 Firmware Version7.80
   BoschCpp6 Version-
BoschAviotec Firmware Version7.61
   BoschAviotec Version-
BoschAviotec Firmware Version7.72
   BoschAviotec Version-
BoschCpp7 Firmware Version7.60
   BoschCpp7 Version-
BoschCpp7 Firmware Version7.61
   BoschCpp7 Version-
BoschCpp7 Firmware Version7.70
   BoschCpp7 Version-
BoschCpp7 Firmware Version7.72
   BoschCpp7 Version-
BoschCpp7 Firmware Version7.80
   BoschCpp7 Version-
BoschCpp7.3 Firmware Version7.60
   BoschCpp7.3 Version-
BoschCpp7.3 Firmware Version7.61
   BoschCpp7.3 Version-
BoschCpp7.3 Firmware Version7.62
   BoschCpp7.3 Version-
BoschCpp7.3 Firmware Version7.70
   BoschCpp7.3 Version-
BoschCpp7.3 Firmware Version7.72
   BoschCpp7.3 Version-
BoschCpp7.3 Firmware Version7.73
   BoschCpp7.3 Version-
BoschCpp7.3 Firmware Version7.80
   BoschCpp7.3 Version-
BoschCpp13 Firmware Version7.75
   BoschCpp13 Version-
BoschCpp14 Firmware Version8.00
   BoschCpp14 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.367
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
psirt@bosch.com 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.