An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM installation this crash also opens the possibility to send further unauthenticated commands to the service. On some products the interface is only local accessible lowering the CVSS base score. For a list of modified CVSS scores, please see the official Bosch Advisory Appendix chapter Modified CVSS Scores for CVE-2021-23859
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HBosch Access Easy Controller
HWBoschall versionsBosch Access Easy Controller Firmware
OSBosch≤ 2.9.1.0Bosch Access Professional Edition
APPBosch≤ 3.8.0Bosch Video Management System
APPBosch10.111.010.0 – 10.0.2 (excl.)≤ 9.0Bosch Building Integration System
APPBosch≤ 4.9Bosch Divar Ip 5000 Firmware
OSBoschall versionsBosch Divar Ip 7000 Firmware
OSBoschall versionsBosch Video Recording Manager
APPBosch4.0 – 4.00.0070≤ 3.813.82 – 3.82.00573.83 – 3.83.0021Bosch Video Recording Manager Exporter
APPBosch2.1 – 2.10.0008
Related vulnerabilities
Nieprawidłowa kontrola dostępu w serwerze RCP+ komponentu Bosch VRM
Brak uwierzytelnienia w Bosch Video Streaming Gateway — pełny dostęp zdalny
RCE przez deserializację w Bosch BVMS Mobile Video Service
Bosch BVMS i powiązane produkty — brak uwierzytelnienia na porcie RCP+
Przepełnienie buforu w produktach Bosch Video/Access — zdalne wykonanie kodu