CVE-2021-23851 affects Bosch cameras, where a specially crafted TCP/IP packet can crash the recovery image web interface and potentially lead to remote code execution via a buffer overflow. This vulnerability has a CVSS score of 7.2 (HIGH), indicating a high impact on confidentiality, integrity, and availability, with a network attack vector and low attack complexity, though it requires administrative rights or physical access to boot the recovery image. Despite its severity, there is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
cpp7.3CPE matchmatch criteria | cpe:2.3:o:bosch:autodome_ip_4000i_firmware:cpp7.3:*:*:*:*:*:*:* | ||
cpp7.3CPE matchmatch criteria | cpe:2.3:o:bosch:autodome_ip_5000i_firmware:cpp7.3:*:*:*:*:*:*:* | ||
cpp7.3CPE matchmatch criteria | cpe:2.3:o:bosch:autodome_ip_starlight_5000i_firmware:cpp7.3:*:*:*:*:*:*:* | ||
cpp7.3CPE matchmatch criteria | cpe:2.3:o:bosch:autodome_ip_starlight_7000i_firmware:cpp7.3:*:*:*:*:*:*:* | ||
cpp7.3CPE matchmatch criteria | cpe:2.3:o:bosch:dinion_ip_3000i_firmware:cpp7.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Buffer Overflow Vulnerability in Recovery Image
Mar 30, 2022Buffer Overflow Vulnerability in Recovery Image
Mar 30, 2022Buffer Overflow Vulnerability in Recovery Image
Mar 30, 2022Buffer Overflow Vulnerability in Recovery Image
Mar 30, 2022Buffer Overflow Vulnerability in Recovery Image
Mar 30, 2022Buffer Overflow Vulnerability in Recovery Image
Mar 30, 2022