CVE-2023-32229
15.06.2023, 11:15
Due to an error in the software interface to the secure element chip on Bosch IP cameras of family CPP13 and CPP14, the chip can be permanently damaged when enabling the Stream security option (signing of the video stream) with option MD5, SHA-1 or SHA-256.Enginsight
Vendor | Product | Version |
---|---|---|
bosch | cpp13_firmware | 𝑥 < 8.48.0017 |
bosch | cpp14_firmware | 8.50 ≤ 𝑥 < 8.80.0090 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-1246 - Improper Write Handling in Limited-write Non-Volatile MemoriesThe product does not implement or incorrectly implements wear leveling operations in limited-write non-volatile memories.
- CWE-400 - Uncontrolled Resource ConsumptionThe software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.