ZeroHour

CVE-2021-23851

CVSS 3.1
7.2 high
EPSS
2%p74
Published
()
Modified
Description

A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in case of a damaged firmware.

Vendors
bosch
Products
autodome ip 4000i firmware, autodome ip 5000i firmware, autodome ip starlight 5000i firmware, autodome ip starlight 7000i firmware, dinion ip 3000i firmware, dinion ip bullet 4000i firmware, dinion ip bullet 5000 firmware, dinion ip bullet 5000i firmware, dinion ip bullet 6000i firmware, flexidome ip 3000i firmware, flexidome ip 4000i firmware, flexidome ip 5000i firmware
Weakness
CWE-121, CWE-120
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.