First published: Wed Jun 09 2021(Updated: )
An error in the handling of a page parameter in Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. This issue only affects versions 7.7x and 7.6x. All other versions are not affected.
Credit: psirt@bosch.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bosch Cpp6 Firmware | =7.62 | |
Bosch Cpp6 Firmware | =7.70 | |
Bosch Cpp6 Firmware | =7.72 | |
Bosch Cpp6 | ||
Bosch Cpp7 Firmware | =7.62 | |
Bosch Cpp7 Firmware | =7.70 | |
Bosch Cpp7 Firmware | =7.72 | |
Bosch Cpp7 | ||
Bosch Cpp7.3 Firmware | =7.62 | |
Bosch Cpp7.3 Firmware | =7.70 | |
Bosch Cpp7.3 Firmware | =7.72 | |
Bosch Cpp7.3 | ||
Bosch Cpp13 Firmware | =7.75 | |
Bosch Cpp13 Firmware | =7.76 | |
Bosch Cpp13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-23854.
The severity of CVE-2021-23854 is high, with a severity value of 6.1.
Versions 7.7x and 7.6x of Bosch IP cameras' firmware are affected by CVE-2021-23854.
To fix CVE-2021-23854, update the firmware of Bosch IP cameras to versions that are not affected (not 7.7x or 7.6x).
More information about CVE-2021-23854 can be found at the following reference: [link](https://psirt.bosch.com/security-advisories/bosch-sa-478243-bt.html)