CVE-2021-23859

Scores

EPSS

0.000none0.0%
0%20%40%60%80%100%

Percentile: 0.0%

CVSS

7.5high3.x
0246810

CVSS Score: 7.5/10

All CVSS Scores

CVSS 3.x
7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS 2.0
5.0

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Description

An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM installation this crash also opens the possibility to send further unauthenticated commands to the service. On some products the interface is only local accessible lowering the CVSS base score. For a list of modified CVSS scores, please see the official Bosch Advisory Appendix chapter Modified CVSS Scores for CVE-2021-23859

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-703

Vulnerable Software (6)

Type: Configuration

Vendor: bosch

Product: access_easy_controller_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:bosch:access_easy_controller_firmware:*:*:*:*:*:*:*:*",          "versionEndIncluding": "2.9.1.0",          "v...

Source: nvd

Type: Configuration

Vendor: bosch

Product: access_professional_edition

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:bosch:access_professional_edition:*:*:*:*:*:*:*:*",      "versionEndIncluding": "3.8.0",      "vulnerable": true    },    {      "cpe23uri": ...

Source: nvd

Type: Configuration

Vendor: bosch

Product: bosch_video_management_system

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:bosch:bosch_video_management_system:*:*:*:*:*:*:*:*",          "versionEndIncluding": "9.0",          "vulnera...

Source: nvd

Type: Configuration

Vendor: bosch

Product: building_integration_system

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:bosch:access_professional_edition:*:*:*:*:*:*:*:*",      "versionEndIncluding": "3.8.0",      "vulnerable": true    },    {      "cpe23uri": ...

Source: nvd

Type: Configuration

Vendor: bosch

Product: video_recording_manager

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:bosch:bosch_video_management_system:*:*:*:*:*:*:*:*",          "versionEndIncluding": "9.0",          "vulnera...

Source: nvd

Type: Configuration

Vendor: bosch

Product: video_recording_manager_exporter

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:bosch:access_professional_edition:*:*:*:*:*:*:*:*",      "versionEndIncluding": "3.8.0",      "vulnerable": true    },    {      "cpe23uri": ...

Source: nvd