CVE-2021-23862: Authenticated Remote Code Execution
A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in system context. This issue also affects installations of the VRM, DIVAR IP, BVMS with VRM installed, the VIDEOJET decoder (VJD-7513 and VJD-8000).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-23862?
CVE-2021-23862 is a vulnerability that allows an authenticated administrative user to execute arbitrary commands in system context by sending a crafted configuration packet.
Which systems are affected by CVE-2021-23862?
CVE-2021-23862 affects installations of Bosch Video Management System (versions up to 10.0.2), Bosch Video Recording Manager (versions up to 4.00.0070), and VIDEOJET decoder (VJD-7513 and VJD-8000).
What is the severity of CVE-2021-23862?
CVE-2021-23862 has a severity rating of 7.2, which is considered critical.
How can I fix CVE-2021-23862?
To fix CVE-2021-23862, upgrade to a version of Bosch Video Management System, Bosch Video Recording Manager, or VIDEOJET decoder that is not vulnerable. Refer to the vendor's security advisory for more information.
Where can I find more information about CVE-2021-23862?
You can find more information about CVE-2021-23862 in Bosch's security advisory at the following URL: https://psirt.bosch.com/security-advisories/bosch-sa-043434-bt.html