« Volver al listado

CVE-2021-23859

Estado: ModificadaAlta (7.5)—

An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM installation this crash also opens the possibility to send further unauthenticated commands to the service. On some products the interface is only local accessible lowering the CVSS base score. For a list of modified CVSS scores, please see the official Bosch Advisory Appendix chapter Modified CVSS Scores for CVE-2021-23859

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (6)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-23859",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@bosch.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@bosch.com",
      "affectedData": [
        {
          "vendor": "Bosch",
          "product": "BVMS",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "9.0.0"
            },
            {
              "status": "affected",
              "version": "11.0",
              "lessThan": "11.0.0",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "10.0",
              "lessThan": "10.0.2",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "10.1",
              "lessThan": "10.1.1",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Bosch",
          "product": "DIVAR IP 7000 R2",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "vendor": "Bosch",
          "product": "DIVAR IP all-in-one 5000",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "vendor": "Bosch",
          "product": "DIVAR IP all-in-one 7000",
          "versions": [
            {
              "status": "affected",
              "version": "all"
            }
          ]
        },
        {
          "vendor": "Bosch",
          "product": "VRM",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "3.81"
            },
            {
              "status": "affected",
              "version": "4.0",
              "versionType": "custom",
              "lessThanOrEqual": "4.00.0070"
            },
            {
              "status": "affected",
              "version": "3.83",
              "versionType": "custom",
              "lessThanOrEqual": "3.83.0021"
            },
            {
              "status": "affected",
              "version": "3.82",
              "versionType": "custom",
              "lessThanOrEqual": "3.82.0057"
            }
          ]
        },
        {
          "vendor": "Bosch",
          "product": "VRM Exporter",
          "versions": [
            {
              "status": "affected",
              "version": "2.1",
              "versionType": "custom",
              "lessThanOrEqual": "2.10.0008"
            }
          ]
        },
        {
          "vendor": "Bosch",
          "product": "APE",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "3.8.x.x"
            }
          ]
        },
        {
          "vendor": "Bosch",
          "product": "AEC",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "2.9.1.x"
            }
          ]
        },
        {
          "vendor": "Bosch",
          "product": "BIS",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "4.9"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "4.8"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "4.7"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-12-08T22:15:08.413",
  "references": [
    {
      "url": "https://psirt.bosch.com/security-advisories/bosch-sa-043434-bt.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@bosch.com"
    },
    {
      "url": "https://psirt.bosch.com/security-advisories/bosch-sa-043434-bt.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@bosch.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-703"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-755"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM installation this crash also opens the possibility to send further unauthenticated commands to the service. On some products the interface is only local accessible lowering the CVSS base score. For a list of modified CVSS scores, please see the official Bosch Advisory Appendix chapter Modified CVSS Scores for CVE-2021-23859"
    },
    {
      "lang": "es",
      "value": "Un atacante no autenticado es capaz de enviar una petición HTTP especial, que causa el bloqueo de un servicio. En el caso de un VRM independiente o de un BVMS con instalación de VRM, este bloqueo también abre la posibilidad de enviar más comandos no autenticados al servicio. En algunos productos, la interfaz sólo es accesible localmente, reduciendo la puntuación base CVSS. Para ver una lista de las puntuaciones CVSS modificadas, consulte el capítulo del apéndice oficial de Bosch Advisory Puntuaciones CVSS modificadas para CVE-2021-23859"
    }
  ],
  "lastModified": "2026-06-17T03:38:56.980",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:bosch:bosch_video_management_system:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B9DD276-15C0-4942-8899-553F7C190320",
              "versionEndIncluding": "9.0"
            },
            {
              "criteria": "cpe:2.3:a:bosch:bosch_video_management_system:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "989D5F9A-D223-4070-82AE-FA79E8B2572C",
              "versionEndExcluding": "10.0.2",
              "versionStartIncluding": "10.0"
            },
            {
              "criteria": "cpe:2.3:a:bosch:bosch_video_management_system:10.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "57FA3EF2-6A7C-46FD-A758-92045A3A2DEE"
            },
            {
              "criteria": "cpe:2.3:a:bosch:bosch_video_management_system:11.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1FF22168-E2A2-47B8-B9BC-104FF1CFDF30"
            },
            {
              "criteria": "cpe:2.3:a:bosch:video_recording_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D54B21E5-8C3E-423F-8E49-9F05B41D540B",
              "versionEndIncluding": "3.81"
            },
            {
              "criteria": "cpe:2.3:a:bosch:video_recording_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "31D1E38A-C0F8-421B-B837-3D2FBD132A18",
              "versionEndIncluding": "3.82.0057",
              "versionStartIncluding": "3.82"
            },
            {
              "criteria": "cpe:2.3:a:bosch:video_recording_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7171D63A-3A1A-4235-9317-009D7C85A93C",
              "versionEndIncluding": "3.83.0021",
              "versionStartIncluding": "3.83"
            },
            {
              "criteria": "cpe:2.3:a:bosch:video_recording_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "31572EBA-C58A-46E8-88EA-ADE04578E039",
              "versionEndIncluding": "4.00.0070",
              "versionStartIncluding": "4.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:bosch:divar_ip_5000_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E2C1615D-2E5F-4D49-B937-05C81AB5414C"
            },
            {
              "criteria": "cpe:2.3:o:bosch:divar_ip_7000_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "7CCD42BE-E4B7-43FC-95FB-C97704E5C268"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:bosch:access_easy_controller_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BD36E262-9272-4A72-B883-CBD84123BEDB",
              "versionEndIncluding": "2.9.1.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:bosch:access_easy_controller:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "50324AEF-BF89-4AAC-B467-FCF87796AB01"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:bosch:access_professional_edition:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "28B735B8-BBBB-43BD-A06C-3297E44DA485",
              "versionEndIncluding": "3.8.0"
            },
            {
              "criteria": "cpe:2.3:a:bosch:building_integration_system:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B01DD4E9-DD97-4B14-8F9E-5EB953939097",
              "versionEndIncluding": "4.9"
            },
            {
              "criteria": "cpe:2.3:a:bosch:video_recording_manager_exporter:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E7DD7CA3-05D7-4AF1-AD9B-117CC3FF22B5",
              "versionEndIncluding": "2.10.0008",
              "versionStartIncluding": "2.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@bosch.com"
}