Vulnerability Details CVE-2021-23850
A specially crafted TCP/IP packet may cause a camera recovery image telnet interface to crash. It may also cause a buffer overflow which could enable remote code execution. The recovery image can only be booted with administrative rights or with physical access to the camera and allows the upload of a new firmware in case of a damaged firmware.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.0%
CVSS Severity
CVSS v3 Score 6.8
CVSS v2 Score 6.5
Products affected by CVE-2021-23850
-
cpe:2.3:h:bosch:autodome_7000:-
-
cpe:2.3:h:bosch:autodome_ip_4000_hd:-
-
cpe:2.3:h:bosch:autodome_ip_4000i:-
-
cpe:2.3:h:bosch:autodome_ip_5000_hd:-
-
cpe:2.3:h:bosch:autodome_ip_5000_ir:-
-
cpe:2.3:h:bosch:autodome_ip_5000i:-
-
cpe:2.3:h:bosch:autodome_ip_starlight_5000i:-
-
cpe:2.3:h:bosch:autodome_ip_starlight_7000i:-
-
cpe:2.3:h:bosch:aviotec_ip_starlight_8000:-
-
cpe:2.3:h:bosch:dinion_hd_1080p:-
-
cpe:2.3:h:bosch:dinion_hd_1080p_hdr:-
-
cpe:2.3:h:bosch:dinion_hd_720p:-
-
cpe:2.3:h:bosch:dinion_imager_9000_hd:-
-
cpe:2.3:h:bosch:dinion_ip_3000i:-
-
cpe:2.3:h:bosch:dinion_ip_4000_hd:-
-
cpe:2.3:h:bosch:dinion_ip_5000_hd:-
-
cpe:2.3:h:bosch:dinion_ip_5000_mp:-
-
cpe:2.3:h:bosch:dinion_ip_bullet_4000:-
-
cpe:2.3:h:bosch:dinion_ip_bullet_4000i:-
-
cpe:2.3:h:bosch:dinion_ip_bullet_5000:-
-
cpe:2.3:h:bosch:dinion_ip_bullet_5000i:-
-
cpe:2.3:h:bosch:dinion_ip_bullet_6000i:-
-
cpe:2.3:h:bosch:dinion_ip_starlight_6000:-
-
cpe:2.3:h:bosch:dinion_ip_starlight_7000:-
-
cpe:2.3:h:bosch:dinion_ip_starlight_7000_hd:-
-
cpe:2.3:h:bosch:dinion_ip_starlight_8000:-
-
cpe:2.3:h:bosch:dinion_ip_thermal_8000:-
-
cpe:2.3:h:bosch:dinion_ip_thermal_9000_rm:-
-
cpe:2.3:h:bosch:dinion_ip_ultra_8000:-
-
cpe:2.3:h:bosch:flexidome_corner_9000_mp:-
-
cpe:2.3:h:bosch:flexidome_hd_1080p:-
-
cpe:2.3:h:bosch:flexidome_hd_1080p_hdr:-
-
cpe:2.3:h:bosch:flexidome_hd_720p:-
-
cpe:2.3:h:bosch:flexidome_ip_3000i:-
-
cpe:2.3:h:bosch:flexidome_ip_4000i:-
-
cpe:2.3:h:bosch:flexidome_ip_5000i:-
-
cpe:2.3:h:bosch:flexidome_ip_indoor_4000_hd:-
-
cpe:2.3:h:bosch:flexidome_ip_indoor_4000_ir:-
-
cpe:2.3:h:bosch:flexidome_ip_indoor_5000_hd:-
-
cpe:2.3:h:bosch:flexidome_ip_indoor_5000_mp:-
-
cpe:2.3:h:bosch:flexidome_ip_micro_2000_hd:-
-
cpe:2.3:h:bosch:flexidome_ip_micro_2000_ip:-
-
cpe:2.3:h:bosch:flexidome_ip_micro_5000_mp:-
-
cpe:2.3:h:bosch:flexidome_ip_outdoor_4000_hd:-
-
cpe:2.3:h:bosch:flexidome_ip_outdoor_4000_ir:-
-
cpe:2.3:h:bosch:flexidome_ip_outdoor_5000_hd:-
-
cpe:2.3:h:bosch:flexidome_ip_outdoor_5000_mp:-
-
cpe:2.3:h:bosch:flexidome_ip_panoramic_5000:-
-
cpe:2.3:h:bosch:flexidome_ip_panoramic_6000:-
-
cpe:2.3:h:bosch:flexidome_ip_panoramic_7000:-
-
cpe:2.3:h:bosch:flexidome_ip_starlight_5000i:-
-
cpe:2.3:h:bosch:flexidome_ip_starlight_6000:-
-
cpe:2.3:h:bosch:flexidome_ip_starlight_7000:-
-
cpe:2.3:h:bosch:flexidome_ip_starlight_8000i:-
-
cpe:2.3:h:bosch:ip_bullet_4000_hd:-
-
cpe:2.3:h:bosch:ip_bullet_5000_hd:-
-
cpe:2.3:h:bosch:ip_micro_2000:-
-
cpe:2.3:h:bosch:ip_micro_2000_hd:-
-
cpe:2.3:h:bosch:mic_ip_dynamic_7000:-
-
cpe:2.3:h:bosch:mic_ip_fusion_9000i:-
-
cpe:2.3:h:bosch:mic_ip_starlight_7000:-
-
cpe:2.3:h:bosch:mic_ip_starlight_7000i:-
-
cpe:2.3:h:bosch:mic_ip_starlight_7100i:-
-
cpe:2.3:h:bosch:mic_ip_ultra_7100i:-
-
cpe:2.3:h:bosch:tinyon_ip_2000:-
-
cpe:2.3:h:bosch:vandal-proof_flexidome_hd_1080p:-
-
cpe:2.3:h:bosch:vandal-proof_flexidome_hd_1080p_hdr:-
-
cpe:2.3:h:bosch:vandal-proof_flexidome_hd_720p:-
-
cpe:2.3:o:bosch:autodome_7000_firmware:cpp4
-
cpe:2.3:o:bosch:autodome_ip_4000_hd_firmware:cpp4
-
cpe:2.3:o:bosch:autodome_ip_4000i_firmware:cpp7.3
-
cpe:2.3:o:bosch:autodome_ip_5000_hd_firmware:cpp4
-
cpe:2.3:o:bosch:autodome_ip_5000_ir_firmware:cpp4
-
cpe:2.3:o:bosch:autodome_ip_5000i_firmware:cpp7.3
-
cpe:2.3:o:bosch:autodome_ip_starlight_5000i_firmware:cpp7.3
-
cpe:2.3:o:bosch:autodome_ip_starlight_7000i_firmware:cpp7.3
-
cpe:2.3:o:bosch:aviotec_ip_starlight_8000_firmware:cpp6
-
cpe:2.3:o:bosch:dinion_hd_1080p_firmware:cpp4
-
cpe:2.3:o:bosch:dinion_hd_1080p_hdr_firmware:cpp4
-
cpe:2.3:o:bosch:dinion_hd_720p_firmware:cpp4
-
cpe:2.3:o:bosch:dinion_imager_9000_hd_firmware:cpp4
-
cpe:2.3:o:bosch:dinion_ip_3000i_firmware:cpp7.3
-
cpe:2.3:o:bosch:dinion_ip_4000_hd_firmware:cpp4
-
cpe:2.3:o:bosch:dinion_ip_5000_hd_firmware:cpp4
-
cpe:2.3:o:bosch:dinion_ip_5000_mp_firmware:cpp4
-
cpe:2.3:o:bosch:dinion_ip_bullet_4000_firmware:cpp4
-
cpe:2.3:o:bosch:dinion_ip_bullet_4000i_firmware:cpp7.3
-
cpe:2.3:o:bosch:dinion_ip_bullet_5000_firmware:cpp4
-
cpe:2.3:o:bosch:dinion_ip_bullet_5000_firmware:cpp7.3
-
cpe:2.3:o:bosch:dinion_ip_bullet_5000i_firmware:cpp7.3
-
cpe:2.3:o:bosch:dinion_ip_bullet_6000i_firmware:cpp7.3
-
cpe:2.3:o:bosch:dinion_ip_starlight_6000_firmware:cpp7
-
cpe:2.3:o:bosch:dinion_ip_starlight_7000_firmware:cpp7
-
cpe:2.3:o:bosch:dinion_ip_starlight_7000_hd_firmware:cpp4
-
cpe:2.3:o:bosch:dinion_ip_starlight_8000_firmware:cpp6
-
cpe:2.3:o:bosch:dinion_ip_thermal_8000_firmware:cpp7
-
cpe:2.3:o:bosch:dinion_ip_thermal_9000_rm_firmware:cpp7
-
cpe:2.3:o:bosch:dinion_ip_ultra_8000_firmware:cpp6
-
cpe:2.3:o:bosch:flexidome_corner_9000_mp_firmware:cpp4
-
cpe:2.3:o:bosch:flexidome_hd_1080p_firmware:cpp4
-
cpe:2.3:o:bosch:flexidome_hd_1080p_hdr_firmware:cpp4
-
cpe:2.3:o:bosch:flexidome_hd_720p_firmware:cpp4
-
cpe:2.3:o:bosch:flexidome_ip_3000i_firmware:cpp7.3
-
cpe:2.3:o:bosch:flexidome_ip_4000i_firmware:cpp7.3
-
cpe:2.3:o:bosch:flexidome_ip_5000i_firmware:cpp7.3
-
cpe:2.3:o:bosch:flexidome_ip_indoor_4000_hd_firmware:cpp4
-
cpe:2.3:o:bosch:flexidome_ip_indoor_4000_ir_firmware:cpp4
-
cpe:2.3:o:bosch:flexidome_ip_indoor_5000_hd_firmware:cpp4
-
cpe:2.3:o:bosch:flexidome_ip_indoor_5000_mp_firmware:cpp4
-
cpe:2.3:o:bosch:flexidome_ip_micro_2000_hd_firmware:cpp4
-
cpe:2.3:o:bosch:flexidome_ip_micro_2000_ip_firmware:cpp4
-
cpe:2.3:o:bosch:flexidome_ip_micro_5000_mp_firmware:cpp4
-
cpe:2.3:o:bosch:flexidome_ip_outdoor_4000_hd_firmware:cpp4
-
cpe:2.3:o:bosch:flexidome_ip_outdoor_4000_ir_firmware:cpp4
-
cpe:2.3:o:bosch:flexidome_ip_outdoor_5000_hd_firmware:cpp4
-
cpe:2.3:o:bosch:flexidome_ip_outdoor_5000_mp_firmware:cpp4
-
cpe:2.3:o:bosch:flexidome_ip_panoramic_5000_firmware:cpp4
-
cpe:2.3:o:bosch:flexidome_ip_panoramic_6000_firmware:cpp6
-
cpe:2.3:o:bosch:flexidome_ip_panoramic_7000_firmware:cpp6
-
cpe:2.3:o:bosch:flexidome_ip_starlight_5000i_firmware:cpp7.3
-
cpe:2.3:o:bosch:flexidome_ip_starlight_6000_firmware:cpp7
-
cpe:2.3:o:bosch:flexidome_ip_starlight_7000_firmware:cpp7
-
cpe:2.3:o:bosch:flexidome_ip_starlight_8000i_firmware:cpp7.3
-
cpe:2.3:o:bosch:ip_bullet_4000_hd_firmware:cpp4
-
cpe:2.3:o:bosch:ip_bullet_5000_hd_firmware:cpp4
-
cpe:2.3:o:bosch:ip_micro_2000_firmware:cpp4
-
cpe:2.3:o:bosch:ip_micro_2000_hd_firmware:cpp4
-
cpe:2.3:o:bosch:mic_ip_dynamic_7000_firmware:cpp4
-
cpe:2.3:o:bosch:mic_ip_fusion_9000i_firmware:cpp7.3
-
cpe:2.3:o:bosch:mic_ip_starlight_7000_firmware:cpp4
-
cpe:2.3:o:bosch:mic_ip_starlight_7000i_firmware:cpp7.3
-
cpe:2.3:o:bosch:mic_ip_starlight_7100i_firmware:cpp7.3
-
cpe:2.3:o:bosch:mic_ip_ultra_7100i_firmware:cpp7.3
-
cpe:2.3:o:bosch:tinyon_ip_2000_firmware:cpp4
-
cpe:2.3:o:bosch:vandal-proof_flexidome_hd_1080p_firmware:cpp4
-
cpe:2.3:o:bosch:vandal-proof_flexidome_hd_1080p_hdr_firmware:cpp4
-
cpe:2.3:o:bosch:vandal-proof_flexidome_hd_720p_firmware:cpp4