An information disclosure vulnerability was discovered in Bosch IP camera devices allowing an unauthenticated attacker to retrieve information (like capabilities) about the device itself and network settings of the device, disclosing possibly internal network settings if the device is connected to the internet.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NBosch Cpp13
HWBoschall versionsBosch Cpp13 Firmware
OSBosch≤ 8.48Bosch Cpp14
HWBoschall versionsBosch Cpp14 Firmware
OSBosch≤ 8.80Bosch Cpp4
HWBoschall versionsBosch Cpp4 Firmware
OSBosch≤ 7.10Bosch Cpp6
HWBoschall versionsBosch Cpp6 Firmware
OSBosch≤ 7.86Bosch Cpp7
HWBoschall versionsBosch Cpp7.3
HWBoschall versionsBosch Cpp7.3 Firmware
OSBosch≤ 7.86Bosch Cpp7 Firmware
OSBosch≤ 7.86
Related vulnerabilities
Pominięcie uwierzytelniania w kamerach IP Bosch CPP6/CPP7
A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administra...
A vulnerability in the web-based interface allows an unauthenticated remote attacker to trigger actions on an ...
In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP header...
An error in the handling of a page parameter in Bosch IP cameras may lead to a reflected cross site scripting ...