MEDIUM · 6.5

CVE-2021-23861

By executing a special command, an user with administrative rights can get access to extended debug functionality on the VRM allowing an impact on integrity or availability of the installed software. ...

Vulnerability Description

By executing a special command, an user with administrative rights can get access to extended debug functionality on the VRM allowing an impact on integrity or availability of the installed software. This issue also affects installations of the DIVAR IP and BVMS with VRM installed.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
BoschBosch Video Management System<= 9.0
BoschVideo Recording Manager<= 3.81
BoschDivar Ip 5000 Firmware-
BoschDivar Ip 7000 Firmware-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-23861?

CVE-2021-23861 is a vulnerability with a CVSS score of 6.5 (MEDIUM). By executing a special command, an user with administrative rights can get access to extended debug functionality on the VRM allowing an impact on integrity or availability of the installed software. ...

How severe is CVE-2021-23861?

CVE-2021-23861 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-23861?

Check the references section above for vendor advisories and patch information. Affected products include: Bosch Bosch Video Management System, Bosch Video Recording Manager, Bosch Divar Ip 5000 Firmware, Bosch Divar Ip 7000 Firmware.