CWE
400 1246
Advisory Published
Updated

CVE-2023-32229

First published: Thu Jun 15 2023(Updated: )

Due to an error in the software interface to the secure element chip on Bosch IP cameras of family CPP13 and CPP14, the chip can be permanently damaged when enabling the Stream security option (signing of the video stream) with option MD5, SHA-1 or SHA-256.

Credit: psirt@bosch.com

Affected SoftwareAffected VersionHow to fix
Bosch Cpp13 Firmware<8.48.0017
Bosch Autodome 7000i
Bosch Autodome 7100 Ir
Bosch Autodome Inteox 7000i
Bosch Dinion Inteox 7100i Ir
Bosch Flexidome Inteox 7100i Ir
Bosch Mic Inteox 7100i
Bosch Cpp14 Firmware>=8.50<8.80.0090
Bosch Dinion 7100i Ir
Bosch Flexidome Indoor 5100i
Bosch Flexidome Indoor 5100i Ir
Bosch Flexidome Multi 7000i
Bosch Flexidome Multi 7000i Ir
Bosch Flexidome Outdoor 5100i
Bosch Flexidome Outdoor 5100i Ir
Bosch Flexidome Panoramic 5100i
Bosch Flexidome Panoramic 5100i Ir

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the vulnerability ID for this issue?

    The vulnerability ID for this issue is CVE-2023-32229.

  • What is the severity of CVE-2023-32229?

    The severity of CVE-2023-32229 is medium with a CVSS score of 6.5.

  • Which Bosch IP camera families are affected by CVE-2023-32229?

    Bosch IP camera families CPP13 and CPP14 are affected by CVE-2023-32229.

  • How can the secure element chip on the affected Bosch IP cameras be permanently damaged?

    The secure element chip on the affected Bosch IP cameras can be permanently damaged when enabling the Stream security option (signing of the video stream) with option MD5, SHA-1 or SHA-256.

  • Is there a fix available for CVE-2023-32229?

    Please refer to the vendor's security advisory at [insert link] for information on available fixes for CVE-2023-32229.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203