First published: Mon Dec 18 2023(Updated: )
A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administrative rights to run arbitrary commands on the OS of the camera.
Credit: psirt@bosch.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Bosch Cpp13 Firmware | <=8.90 | |
Bosch Cpp13 Firmware | ||
All of | ||
Bosch Cpp14 Firmware | >=8.20<=8.81 | |
Bosch Cpp14 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39509 is considered a critical severity vulnerability due to the potential for unauthorized command execution on affected Bosch IP cameras.
To remediate CVE-2023-39509, update the Bosch Cpp13 or Cpp14 firmware to the latest version that addresses this vulnerability.
CVE-2023-39509 affects Bosch Cpp13 and Cpp14 IP cameras running specific firmware versions.
Authenticated users with administrative rights to Bosch IP cameras are primarily impacted by CVE-2023-39509.
CVE-2023-39509 is a command injection vulnerability that allows an authenticated user to execute arbitrary commands on the camera's operating system.