SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-23850

A specially crafted TCP/IP packet may cause a camera recovery image telnet interface to crash.

HIGH 7.2EPSS 1.56%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.56%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A specially crafted TCP/IP packet may cause a camera recovery image telnet interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in case of a damaged firmware.

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
1.56% probability · 74th percentile
CISA KEV
Not listed
Weakness
CWE-121, CWE-120
Affected
bosch/autodome ip 4000i firmware · bosch/autodome ip 5000i firmware · bosch/autodome ip starlight 5000i firmware · bosch/autodome ip starlight 7000i firmware · bosch/dinion ip 3000i firmware · bosch/dinion ip bullet 4000i firmware · bosch/dinion ip bullet 5000 firmware · bosch/dinion ip bullet 5000i firmware · bosch/dinion ip bullet 6000i firmware · bosch/flexidome ip 3000i firmware · bosch/flexidome ip 4000i firmware · bosch/flexidome ip 5000i firmware · bosch/flexidome ip starlight 5000i firmware · bosch/flexidome ip starlight 8000i firmware · bosch/mic ip starlight 7000i firmware · bosch/mic ip starlight 7100i firmware · bosch/mic ip ultra 7100i firmware · bosch/mic ip fusion 9000i firmware · bosch/dinion ip starlight 6000 firmware · bosch/dinion ip starlight 7000 firmware · +40 more
Source
psirt@bosch.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.