CVE-2023-39509: Command Injection
A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administrative rights to run arbitrary commands on the OS of the camera.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-39509?
CVE-2023-39509 is considered a critical severity vulnerability due to the potential for unauthorized command execution on affected Bosch IP cameras.
How do I fix CVE-2023-39509?
To remediate CVE-2023-39509, update the Bosch Cpp13 or Cpp14 firmware to the latest version that addresses this vulnerability.
What devices are affected by CVE-2023-39509?
CVE-2023-39509 affects Bosch Cpp13 and Cpp14 IP cameras running specific firmware versions.
Who is impacted by CVE-2023-39509?
Authenticated users with administrative rights to Bosch IP cameras are primarily impacted by CVE-2023-39509.
What type of vulnerability is CVE-2023-39509?
CVE-2023-39509 is a command injection vulnerability that allows an authenticated user to execute arbitrary commands on the camera's operating system.