MEDIUM🇵🇱 Wersja polska

CVE-2021-23842

CVSS 5.7v3.1pub. 2022-01-19upd. 2024-11-21

Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An attacker could retrieve the key from the firmware to decrypt network traffic between the AMC2 and the host system. Thus, an attacker can exploit this vulnerability to decrypt and modify network traffic, decrypt and further investigate the device\'s firmware file, and change the device configuration. The attacker needs to have access to the local network, typically even the same subnet.

CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
  • Bosch Access Management System

    APP
    Bosch
    3.0
  • Bosch Access Professional Edition

    APP
    Bosch
    ≤ 3.8.0
  • Bosch Amc2

    HW
    Bosch
    all versions
  • Bosch Amc2 Firmware

    OS
    Bosch
    all versions
  • Bosch Building Integration System

    APP
    Bosch
    < 4.9.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-23859CRITICAL9.1PL ✓same product

Bosch BVMS/VRM — nieuwierzytelniona awaria usługi i obejście autoryzacji

CVE-2019-6957CRITICAL9.8PL ✓same product

Przepełnienie buforu w produktach Bosch Video/Access — zdalne wykonanie kodu

CVE-2019-6958CRITICAL9.1PL ✓same product

Bosch BVMS i powiązane produkty — brak uwierzytelnienia na porcie RCP+

CVE-2023-29241HIGH8.1same product

Improper Information in Cybersecurity Guidebook in Bosch Building Integration System (BIS) 5.0 may lead to wro...

CVE-2021-23843HIGH8.8same product

The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC...