6.8
CVSSv2

CVE-2021-23849

Published: 05/08/2021 Updated: 12/08/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A vulnerability in the web-based interface allows an unauthenticated remote malicious user to trigger actions on an affected system on behalf of another user (CSRF - Cross Site Request Forgery). This requires the victim to be tricked into clicking a malicious link or opening a malicious website while being logged in into the camera.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bosch cpp4_firmware 7.10

bosch cpp6_firmware 7.60

bosch cpp6_firmware 7.61

bosch cpp6_firmware 7.70

bosch cpp6_firmware 7.80

bosch aviotec_firmware 7.61

bosch aviotec_firmware 7.72

bosch cpp7_firmware 7.60

bosch cpp7_firmware 7.61

bosch cpp7_firmware 7.70

bosch cpp7_firmware 7.72

bosch cpp7_firmware 7.80

bosch cpp7.3_firmware 7.60

bosch cpp7.3_firmware 7.61

bosch cpp7.3_firmware 7.62

bosch cpp7.3_firmware 7.70

bosch cpp7.3_firmware 7.72

bosch cpp7.3_firmware 7.73

bosch cpp7.3_firmware 7.80

bosch cpp13_firmware 7.75

bosch cpp14_firmware 8.00