7.2

CVE-2021-23851

A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in case of a damaged firmware.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BoschAutodome Ip 4000i Firmware Versioncpp7.3
   BoschAutodome Ip 4000i Version-
BoschAutodome Ip 5000i Firmware Versioncpp7.3
   BoschAutodome Ip 5000i Version-
BoschDinion Ip 3000i Firmware Versioncpp7.3
   BoschDinion Ip 3000i Version-
BoschDinion Ip Bullet 4000i Firmware Versioncpp7.3
   BoschDinion Ip Bullet 4000i Version-
BoschDinion Ip Bullet 5000 Firmware Versioncpp7.3
   BoschDinion Ip Bullet 5000 Version-
BoschDinion Ip Bullet 5000i Firmware Versioncpp7.3
   BoschDinion Ip Bullet 5000i Version-
BoschDinion Ip Bullet 6000i Firmware Versioncpp7.3
   BoschDinion Ip Bullet 6000i Version-
BoschFlexidome Ip 3000i Firmware Versioncpp7.3
   BoschFlexidome Ip 3000i Version-
BoschFlexidome Ip 4000i Firmware Versioncpp7.3
   BoschFlexidome Ip 4000i Version-
BoschFlexidome Ip 5000i Firmware Versioncpp7.3
   BoschFlexidome Ip 5000i Version-
BoschMic Ip Starlight 7000i Firmware Versioncpp7.3
   BoschMic Ip Starlight 7000i Version-
BoschMic Ip Starlight 7100i Firmware Versioncpp7.3
   BoschMic Ip Starlight 7100i Version-
BoschMic Ip Ultra 7100i Firmware Versioncpp7.3
   BoschMic Ip Ultra 7100i Version-
BoschMic Ip Fusion 9000i Firmware Versioncpp7.3
   BoschMic Ip Fusion 9000i Version-
BoschDinion Ip Ultra 8000 Firmware Versioncpp6
   BoschDinion Ip Ultra 8000 Version-
BoschAutodome Ip 4000 Hd Firmware Versioncpp4
   BoschAutodome Ip 4000 Hd Version-
BoschAutodome Ip 5000 Hd Firmware Versioncpp4
   BoschAutodome Ip 5000 Hd Version-
BoschAutodome Ip 5000 Ir Firmware Versioncpp4
   BoschAutodome Ip 5000 Ir Version-
BoschAutodome 7000 Firmware Versioncpp4
   BoschAutodome 7000 Version-
BoschDinion Hd 1080p Firmware Versioncpp4
   BoschDinion Hd 1080p Version-
BoschDinion Hd 1080p Hdr Firmware Versioncpp4
   BoschDinion Hd 1080p Hdr Version-
BoschDinion Hd 720p Firmware Versioncpp4
   BoschDinion Hd 720p Version-
BoschDinion Ip 4000 Hd Firmware Versioncpp4
   BoschDinion Ip 4000 Hd Version-
BoschDinion Ip 5000 Hd Firmware Versioncpp4
   BoschDinion Ip 5000 Hd Version-
BoschDinion Ip 5000 Mp Firmware Versioncpp4
   BoschDinion Ip 5000 Mp Version-
BoschFlexidome Hd 1080p Firmware Versioncpp4
   BoschFlexidome Hd 1080p Version-
BoschFlexidome Hd 720p Firmware Versioncpp4
   BoschFlexidome Hd 720p Version-
BoschIp Bullet 4000 Hd Firmware Versioncpp4
   BoschIp Bullet 4000 Hd Version-
BoschIp Bullet 5000 Hd Firmware Versioncpp4
   BoschIp Bullet 5000 Hd Version-
BoschIp Micro 2000 Firmware Versioncpp4
   BoschIp Micro 2000 Version-
BoschIp Micro 2000 Hd Firmware Versioncpp4
   BoschIp Micro 2000 Hd Version-
BoschMic Ip Dynamic 7000 Firmware Versioncpp4
   BoschMic Ip Dynamic 7000 Version-
BoschTinyon Ip 2000 Firmware Versioncpp4
   BoschTinyon Ip 2000 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.465
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
psirt@bosch.com 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.

CWE-121 Stack-based Buffer Overflow

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).