CVE-2021-23851

CVSS V2 Medium 6.5 CVSS V3 High 7.2
Description
A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in case of a damaged firmware.
Overview
  • CVE ID
  • CVE-2021-23851
  • Assigner
  • psirt@bosch.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2022-03-30T16:15:08
  • Last Modified Date
  • 2022-04-08T17:29:44
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
AND
cpe:2.3:o:bosch:autodome_ip_4000i_firmware:cpp7.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:autodome_ip_4000i:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:autodome_ip_5000i_firmware:cpp7.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:autodome_ip_5000i:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:autodome_ip_starlight_5000i_firmware:cpp7.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:autodome_ip_starlight_5000i:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:autodome_ip_starlight_7000i_firmware:cpp7.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:autodome_ip_starlight_7000i:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:dinion_ip_3000i_firmware:cpp7.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:dinion_ip_3000i:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:dinion_ip_bullet_4000i_firmware:cpp7.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:dinion_ip_bullet_4000i:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:dinion_ip_bullet_5000_firmware:cpp7.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:dinion_ip_bullet_5000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:dinion_ip_bullet_5000i_firmware:cpp7.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:dinion_ip_bullet_5000i:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:dinion_ip_bullet_6000i_firmware:cpp7.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:dinion_ip_bullet_6000i:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_ip_3000i_firmware:cpp7.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_ip_3000i:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_ip_4000i_firmware:cpp7.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_ip_4000i:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_ip_5000i_firmware:cpp7.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_ip_5000i:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_ip_starlight_5000i_firmware:cpp7.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_ip_starlight_5000i:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_ip_starlight_8000i_firmware:cpp7.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_ip_starlight_8000i:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:mic_ip_starlight_7000i_firmware:cpp7.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:mic_ip_starlight_7000i:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:mic_ip_starlight_7100i_firmware:cpp7.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:mic_ip_starlight_7100i:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:mic_ip_ultra_7100i_firmware:cpp7.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:mic_ip_ultra_7100i:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:mic_ip_fusion_9000i_firmware:cpp7.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:mic_ip_fusion_9000i:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:dinion_ip_starlight_6000_firmware:cpp7:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:dinion_ip_starlight_6000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:dinion_ip_starlight_7000_firmware:cpp7:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:dinion_ip_starlight_7000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:dinion_ip_thermal_8000_firmware:cpp7:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:dinion_ip_thermal_8000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_ip_starlight_6000_firmware:cpp7:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_ip_starlight_6000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_ip_starlight_7000_firmware:cpp7:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_ip_starlight_7000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:dinion_ip_thermal_9000_rm_firmware:cpp7:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:dinion_ip_thermal_9000_rm:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:aviotec_ip_starlight_8000_firmware:cpp6:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:aviotec_ip_starlight_8000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:dinion_ip_starlight_8000_firmware:cpp6:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:dinion_ip_starlight_8000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:dinion_ip_ultra_8000_firmware:cpp6:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:dinion_ip_ultra_8000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_ip_panoramic_6000_firmware:cpp6:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_ip_panoramic_6000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_ip_panoramic_7000_firmware:cpp6:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_ip_panoramic_7000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:autodome_ip_4000_hd_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:autodome_ip_4000_hd:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:autodome_ip_5000_hd_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:autodome_ip_5000_hd:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:autodome_ip_5000_ir_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:autodome_ip_5000_ir:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:autodome_7000_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:autodome_7000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:dinion_hd_1080p_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:dinion_hd_1080p:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:dinion_hd_1080p_hdr_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:dinion_hd_1080p_hdr:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:dinion_hd_720p_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:dinion_hd_720p:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:dinion_imager_9000_hd_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:dinion_imager_9000_hd:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:dinion_ip_bullet_4000_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:dinion_ip_bullet_4000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:dinion_ip_bullet_5000_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:dinion_ip_bullet_5000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:dinion_ip_4000_hd_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:dinion_ip_4000_hd:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:dinion_ip_5000_hd_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:dinion_ip_5000_hd:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:dinion_ip_5000_mp_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:dinion_ip_5000_mp:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:dinion_ip_starlight_7000_hd_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:dinion_ip_starlight_7000_hd:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_corner_9000_mp_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_corner_9000_mp:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_hd_1080p_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_hd_1080p:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_hd_1080p_hdr_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_hd_1080p_hdr:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_hd_720p_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_hd_720p:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:vandal-proof_flexidome_hd_1080p_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:vandal-proof_flexidome_hd_1080p:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:vandal-proof_flexidome_hd_1080p_hdr_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:vandal-proof_flexidome_hd_1080p_hdr:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:vandal-proof_flexidome_hd_720p_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:vandal-proof_flexidome_hd_720p:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_ip_micro_2000_hd_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_ip_micro_2000_hd:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_ip_micro_2000_ip_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_ip_micro_2000_ip:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_ip_indoor_4000_hd_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_ip_indoor_4000_hd:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_ip_indoor_4000_ir_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_ip_indoor_4000_ir:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_ip_outdoor_4000_hd_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_ip_outdoor_4000_hd:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_ip_outdoor_4000_ir_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_ip_outdoor_4000_ir:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_ip_indoor_5000_hd_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_ip_indoor_5000_hd:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_ip_indoor_5000_mp_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_ip_indoor_5000_mp:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_ip_micro_5000_mp_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_ip_micro_5000_mp:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_ip_outdoor_5000_hd_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_ip_outdoor_5000_hd:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_ip_outdoor_5000_mp_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_ip_outdoor_5000_mp:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:flexidome_ip_panoramic_5000_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:flexidome_ip_panoramic_5000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:ip_bullet_4000_hd_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:ip_bullet_4000_hd:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:ip_bullet_5000_hd_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:ip_bullet_5000_hd:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:ip_micro_2000_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:ip_micro_2000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:ip_micro_2000_hd_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:ip_micro_2000_hd:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:mic_ip_dynamic_7000_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:mic_ip_dynamic_7000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:mic_ip_starlight_7000_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:mic_ip_starlight_7000:-:*:*:*:*:*:*:* 0 OR
AND
cpe:2.3:o:bosch:tinyon_ip_2000_firmware:cpp4:*:*:*:*:*:*:* 1 OR
cpe:2.3:h:bosch:tinyon_ip_2000:-:*:*:*:*:*:*:* 0 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:L/Au:S/C:P/I:P/A:P
  • Access Vector
  • NETWORK
  • Access Compatibility
  • LOW
  • Authentication
  • SINGLE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • PARTIAL
  • Base Score
  • 6.5
  • Severity
  • MEDIUM
  • Exploitability Score
  • 8
  • Impact Score
  • 6.4
CVSS Version 3
  • Version
  • 3.1
  • Vector String
  • CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Attack Vector
  • NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • HIGH
  • User Interaction
  • NONE
  • Scope
  • UNCHANGED
  • Confidentiality Impact
  • HIGH
  • Availability Impact
  • HIGH
  • Base Score
  • 7.2
  • Base Severity
  • HIGH
  • Exploitability Score
  • 1.2
  • Impact Score
  • 5.9
References
History
Created Old Value New Value Data Type Notes
2022-04-04 00:40:11 Added to TrackCVE
2022-12-06 13:42:02 2022-03-30T16:15Z 2022-03-30T16:15:08 CVE Published Date updated
2022-12-06 13:42:02 2022-04-08T17:29:44 CVE Modified Date updated
2022-12-06 13:42:02 Analyzed Vulnerability Status updated
2022-12-06 13:42:09 References updated