5.3

CVE-2022-41677

An information disclosure vulnerability was discovered in Bosch IP camera devices allowing an unauthenticated attacker to retrieve information (like capabilities) about the device itself and network settings of the device, disclosing possibly internal network settings if the device is connected to the internet.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bosch ≫ Cpp14 Firmware Version <= 8.80
   Bosch ≫ Cpp14 Version -
Bosch ≫ Cpp13 Firmware Version <= 8.48
   Bosch ≫ Cpp13 Version -
Bosch ≫ Cpp7.3 Firmware Version <= 7.86
   Bosch ≫ Cpp7.3 Version -
Bosch ≫ Cpp7 Firmware Version <= 7.86
   Bosch ≫ Cpp7 Version -
Bosch ≫ Cpp6 Firmware Version <= 7.86
   Bosch ≫ Cpp6 Version -
Bosch ≫ Cpp4 Firmware Version <= 7.10
   Bosch ≫ Cpp4 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.6% 0.453
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Bosch 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://psirt.bosch.com/security-advisories/bosch-sa-839739-BT.html
Vendor Advisory