CVE-2023-32229: Medium severity bosch cpp13 firmware vulnerability
Due to an error in the software interface to the secure element chip on Bosch IP cameras of family CPP13 and CPP14, the chip can be permanently damaged when enabling the Stream security option (signing of the video stream) with option MD5, SHA-1 or SHA-256.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-32229.
What is the severity of CVE-2023-32229?
The severity of CVE-2023-32229 is medium with a CVSS score of 6.5.
Which Bosch IP camera families are affected by CVE-2023-32229?
Bosch IP camera families CPP13 and CPP14 are affected by CVE-2023-32229.
How can the secure element chip on the affected Bosch IP cameras be permanently damaged?
The secure element chip on the affected Bosch IP cameras can be permanently damaged when enabling the Stream security option (signing of the video stream) with option MD5, SHA-1 or SHA-256.
Is there a fix available for CVE-2023-32229?
Please refer to the vendor's security advisory at [insert link] for information on available fixes for CVE-2023-32229.