First published: Wed Jun 09 2021(Updated: )
An error in the URL handler Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the camera address can send a crafted link to a user, which will execute javascript code in the context of the user.
Credit: psirt@bosch.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bosch Cpp4 Firmware | ||
Bosch Cpp4 | ||
Bosch Cpp6 Firmware | ||
Bosch Cpp6 | ||
Bosch Cpp7 Firmware | ||
Bosch Cpp7 | ||
Bosch Cpp7.3 Firmware | ||
Bosch Cpp7.3 | ||
Bosch Cpp13 Firmware | ||
Bosch Cpp13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23848 is a vulnerability in the URL handler of Bosch IP cameras that can lead to a reflected cross-site scripting (XSS) attack.
This vulnerability allows an attacker with knowledge of the camera address to send a crafted link to a user, which will execute JavaScript code in the user's context.
CVE-2021-23848 has a severity rating of 6.1 (high).
Bosch IP cameras with Cpp4 Firmware, Cpp6 Firmware, Cpp7 Firmware, Cpp7.3 Firmware, and Cpp13 Firmware are affected.
To mitigate CVE-2021-23848, it is recommended to update the firmware of the affected Bosch IP cameras to the latest version provided by the vendor.