6.1
CVE-2021-23860
- EPSS 0.25%
- Veröffentlicht 08.12.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 05:51:58
- Quelle psirt@bosch.com
- CVE-Watchlists
- Unerledigt
An error in a page handler of the VRM may lead to a reflected cross site scripting (XSS) in the web-based interface. To exploit this vulnerability an attack must be able to modify the HTTP header that is sent. This issue also affects installations of the DIVAR IP and BVMS with VRM installed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bosch ≫ Bosch Video Management System Version <= 9.0
Bosch ≫ Bosch Video Management System Version >= 10.0 < 10.0.2
Bosch ≫ Bosch Video Management System Version10.1
Bosch ≫ Bosch Video Management System Version11.0
Bosch ≫ Video Recording Manager Version <= 3.81
Bosch ≫ Video Recording Manager Version >= 3.82 <= 3.82.0057
Bosch ≫ Video Recording Manager Version >= 3.83 <= 3.83.0021
Bosch ≫ Video Recording Manager Version >= 4.0 <= 4.00.0070
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.455 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
| psirt@bosch.com | 5 | 1.6 | 3.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.