CVE-2021-23849
05.08.2021, 20:15
A vulnerability in the web-based interface allows an unauthenticated remote attacker to trigger actions on an affected system on behalf of another user (CSRF - Cross Site Request Forgery). This requires the victim to be tricked into clicking a malicious link or opening a malicious website while being logged in into the camera.
Vendor | Product | Version |
---|---|---|
bosch | cpp4_firmware | 7.10 |
bosch | cpp6_firmware | 7.60 |
bosch | cpp6_firmware | 7.61 |
bosch | cpp6_firmware | 7.70 |
bosch | cpp6_firmware | 7.80 |
bosch | aviotec_firmware | 7.61 |
bosch | aviotec_firmware | 7.72 |
bosch | cpp7_firmware | 7.60 |
bosch | cpp7_firmware | 7.61 |
bosch | cpp7_firmware | 7.70 |
bosch | cpp7_firmware | 7.72 |
bosch | cpp7_firmware | 7.80 |
bosch | cpp7.3_firmware | 7.60 |
bosch | cpp7.3_firmware | 7.61 |
bosch | cpp7.3_firmware | 7.62 |
bosch | cpp7.3_firmware | 7.70 |
bosch | cpp7.3_firmware | 7.72 |
bosch | cpp7.3_firmware | 7.73 |
bosch | cpp7.3_firmware | 7.80 |
bosch | cpp13_firmware | 7.75 |
bosch | cpp14_firmware | 8.00 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration