CVE-2021-23849

A vulnerability in the web-based interface allows an unauthenticated remote attacker to trigger actions on an affected system on behalf of another user (CSRF - Cross Site Request Forgery). This requires the victim to be tricked into clicking a malicious link or opening a malicious website while being logged in into the camera.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
boschCNA
7.5 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
VendorProductVersion
boschcpp4_firmware
7.10
boschcpp6_firmware
7.60
boschcpp6_firmware
7.61
boschcpp6_firmware
7.70
boschcpp6_firmware
7.80
boschaviotec_firmware
7.61
boschaviotec_firmware
7.72
boschcpp7_firmware
7.60
boschcpp7_firmware
7.61
boschcpp7_firmware
7.70
boschcpp7_firmware
7.72
boschcpp7_firmware
7.80
boschcpp7.3_firmware
7.60
boschcpp7.3_firmware
7.61
boschcpp7.3_firmware
7.62
boschcpp7.3_firmware
7.70
boschcpp7.3_firmware
7.72
boschcpp7.3_firmware
7.73
boschcpp7.3_firmware
7.80
boschcpp13_firmware
7.75
boschcpp14_firmware
8.00
𝑥
= Vulnerable software versions