{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-22T22:02:07.032","vulnerabilities":[{"cve":{"id":"CVE-2021-23859","sourceIdentifier":"psirt@bosch.com","published":"2021-12-08T22:15:08.413","lastModified":"2024-11-21T05:51:58.003","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM installation this crash also opens the possibility to send further unauthenticated commands to the service. On some products the interface is only local accessible lowering the CVSS base score. For a list of modified CVSS scores, please see the official Bosch Advisory Appendix chapter Modified CVSS Scores for CVE-2021-23859"},{"lang":"es","value":"Un atacante no autenticado es capaz de enviar una petición HTTP especial, que causa el bloqueo de un servicio. En el caso de un VRM independiente o de un BVMS con instalación de VRM, este bloqueo también abre la posibilidad de enviar más comandos no autenticados al servicio. En algunos productos, la interfaz sólo es accesible localmente, reduciendo la puntuación base CVSS. Para ver una lista de las puntuaciones CVSS modificadas, consulte el capítulo del apéndice oficial de Bosch Advisory Puntuaciones CVSS modificadas para CVE-2021-23859"}],"metrics":{"cvssMetricV31":[{"source":"psirt@bosch.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"psirt@bosch.com","type":"Secondary","description":[{"lang":"en","value":"CWE-703"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-755"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:bosch:bosch_video_management_system:*:*:*:*:*:*:*:*","versionEndIncluding":"9.0","matchCriteriaId":"0B9DD276-15C0-4942-8899-553F7C190320"},{"vulnerable":true,"criteria":"cpe:2.3:a:bosch:bosch_video_management_system:*:*:*:*:*:*:*:*","versionStartIncluding":"10.0","versionEndExcluding":"10.0.2","matchCriteriaId":"989D5F9A-D223-4070-82AE-FA79E8B2572C"},{"vulnerable":true,"criteria":"cpe:2.3:a:bosch:bosch_video_management_system:10.1:*:*:*:*:*:*:*","matchCriteriaId":"57FA3EF2-6A7C-46FD-A758-92045A3A2DEE"},{"vulnerable":true,"criteria":"cpe:2.3:a:bosch:bosch_video_management_system:11.0:*:*:*:*:*:*:*","matchCriteriaId":"1FF22168-E2A2-47B8-B9BC-104FF1CFDF30"},{"vulnerable":true,"criteria":"cpe:2.3:a:bosch:video_recording_manager:*:*:*:*:*:*:*:*","versionEndIncluding":"3.81","matchCriteriaId":"D54B21E5-8C3E-423F-8E49-9F05B41D540B"},{"vulnerable":true,"criteria":"cpe:2.3:a:bosch:video_recording_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"3.82","versionEndIncluding":"3.82.0057","matchCriteriaId":"31D1E38A-C0F8-421B-B837-3D2FBD132A18"},{"vulnerable":true,"criteria":"cpe:2.3:a:bosch:video_recording_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"3.83","versionEndIncluding":"3.83.0021","matchCriteriaId":"7171D63A-3A1A-4235-9317-009D7C85A93C"},{"vulnerable":true,"criteria":"cpe:2.3:a:bosch:video_recording_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndIncluding":"4.00.0070","matchCriteriaId":"31572EBA-C58A-46E8-88EA-ADE04578E039"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:bosch:divar_ip_5000_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"E2C1615D-2E5F-4D49-B937-05C81AB5414C"},{"vulnerable":false,"criteria":"cpe:2.3:o:bosch:divar_ip_7000_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"7CCD42BE-E4B7-43FC-95FB-C97704E5C268"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:bosch:access_easy_controller_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"2.9.1.0","matchCriteriaId":"BD36E262-9272-4A72-B883-CBD84123BEDB"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:bosch:access_easy_controller:-:*:*:*:*:*:*:*","matchCriteriaId":"50324AEF-BF89-4AAC-B467-FCF87796AB01"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:bosch:access_professional_edition:*:*:*:*:*:*:*:*","versionEndIncluding":"3.8.0","matchCriteriaId":"28B735B8-BBBB-43BD-A06C-3297E44DA485"},{"vulnerable":true,"criteria":"cpe:2.3:a:bosch:building_integration_system:*:*:*:*:*:*:*:*","versionEndIncluding":"4.9","matchCriteriaId":"B01DD4E9-DD97-4B14-8F9E-5EB953939097"},{"vulnerable":true,"criteria":"cpe:2.3:a:bosch:video_recording_manager_exporter:*:*:*:*:*:*:*:*","versionStartIncluding":"2.1","versionEndIncluding":"2.10.0008","matchCriteriaId":"E7DD7CA3-05D7-4AF1-AD9B-117CC3FF22B5"}]}]}],"references":[{"url":"https://psirt.bosch.com/security-advisories/bosch-sa-043434-bt.html","source":"psirt@bosch.com","tags":["Vendor Advisory"]},{"url":"https://psirt.bosch.com/security-advisories/bosch-sa-043434-bt.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}