CVE-2021-23848: Reflected XSS in URL handler
An error in the URL handler Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the camera address can send a crafted link to a user, which will execute javascript code in the context of the user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-23848?
CVE-2021-23848 is a vulnerability in the URL handler of Bosch IP cameras that can lead to a reflected cross-site scripting (XSS) attack.
How does CVE-2021-23848 work?
This vulnerability allows an attacker with knowledge of the camera address to send a crafted link to a user, which will execute JavaScript code in the user's context.
What is the severity of CVE-2021-23848?
CVE-2021-23848 has a severity rating of 6.1 (high).
Which software versions are affected by CVE-2021-23848?
Bosch IP cameras with Cpp4 Firmware, Cpp6 Firmware, Cpp7 Firmware, Cpp7.3 Firmware, and Cpp13 Firmware are affected.
How can CVE-2021-23848 be mitigated?
To mitigate CVE-2021-23848, it is recommended to update the firmware of the affected Bosch IP cameras to the latest version provided by the vendor.