HIGH · 8.8

CVE-2021-23843

The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a password protection on configured devices to restrict...

Vulnerability Description

The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a password protection on configured devices to restrict access to the configuration of an AMC2. An attacker can circumvent this protection and make unauthorized changes to configuration data on the device. An attacker can exploit this vulnerability to manipulate the device\'s configuration or make it unresponsive in the local network. The attacker needs to have access to the local network, typically even the same subnet.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
BoschAmc2 Firmware-
BoschAmc2-
BoschAccess Management System3.0
BoschAccess Professional Edition<= 3.8.0
BoschBuilding Integration System< 4.9.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-23843?

CVE-2021-23843 is a vulnerability with a CVSS score of 8.8 (HIGH). The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a password protection on configured devices to restrict...

How severe is CVE-2021-23843?

CVE-2021-23843 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-23843?

Check the references section above for vendor advisories and patch information. Affected products include: Bosch Amc2 Firmware, Bosch Amc2, Bosch Access Management System, Bosch Access Professional Edition, Bosch Building Integration System.