CVE-2021-23854: Reflected XSS in page parameter
Published Jun 9, 2021
·Updated
An error in the handling of a page parameter in Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. This issue only affects versions 7.7x and 7.6x. All other versions are not affected.
Affected Software
15 affected components
Bosch Cpp6 Firmware=7.62
Bosch Cpp6 Firmware=7.70
Bosch Cpp6 Firmware=7.72
Bosch CPP6
Bosch Cpp7 Firmware=7.62
Bosch Cpp7 Firmware=7.70
Bosch Cpp7 Firmware=7.72
Bosch CPP7
Bosch Cpp7.3 Firmware=7.62
Bosch Cpp7.3 Firmware=7.70
Bosch Cpp7.3 Firmware=7.72
Bosch CPP7.3
Bosch Cpp13 Firmware=7.75
Bosch Cpp13 Firmware=7.76
Bosch Cpp13
Event History
Jun 9, 2021
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-23854.
2
What is the severity of CVE-2021-23854?
The severity of CVE-2021-23854 is high, with a severity value of 6.1.
3
Which software versions are affected by CVE-2021-23854?
Versions 7.7x and 7.6x of Bosch IP cameras' firmware are affected by CVE-2021-23854.
4
How can I fix CVE-2021-23854?
To fix CVE-2021-23854, update the firmware of Bosch IP cameras to versions that are not affected (not 7.7x or 7.6x).
5
Where can I find more information about CVE-2021-23854?
More information about CVE-2021-23854 can be found at the following reference: [link](https://psirt.bosch.com/security-advisories/bosch-sa-478243-bt.html)