In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP headers through crafted URLs.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:HBosch Cpp13
HWBoschall versionsBosch Cpp13 Firmware
OSBoschall versionsBosch Cpp4
HWBoschall versionsBosch Cpp4 Firmware
OSBoschall versionsBosch Cpp6
HWBoschall versionsBosch Cpp6 Firmware
OSBoschall versionsBosch Cpp7
HWBoschall versionsBosch Cpp7.3
HWBoschall versionsBosch Cpp7.3 Firmware
OSBoschall versionsBosch Cpp7 Firmware
OSBoschall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2021-23847CRITICAL9.8PL ✓same product
Pominięcie uwierzytelniania w kamerach IP Bosch CPP6/CPP7
CVE-2023-39509HIGH7.2same product
A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administra...
CVE-2021-23849HIGH7.5same product
A vulnerability in the web-based interface allows an unauthenticated remote attacker to trigger actions on an ...
CVE-2021-23854HIGH8.3same product
An error in the handling of a page parameter in Bosch IP cameras may lead to a reflected cross site scripting ...
CVE-2021-23848HIGH8.3same product
An error in the URL handler Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-bas...