CVE-2021-23859
An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM installation this crash also opens the possibility to send further unauthenticated commands to the service. On some products the interface is only local accessible lowering the CVSS base score. For a list of modified CVSS scores, please see the official Bosch Advisory Appendix chapter Modified CVSS Scores for CVE-2021-23859
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- EPSS probability
- 0.29%
- CWE
- CWE-703
- Published
- 2021-12-08
- Last modified
- 2026-03-13
Affected products
- Bosch BVMS
- Bosch BVMS
- Bosch BVMS
- Bosch BVMS
- Bosch DIVAR IP 7000 R2
- Bosch DIVAR IP all-in-one 5000
- Bosch DIVAR IP all-in-one 7000
- Bosch VRM
Weakness type
Related vulnerabilities
- CVE-2023-0397 — DoS: Invalid Initialization in le_read_buffer_size_complete
- CVE-2021-3329 — DOS: Incorrect handling of the initial HCI ACL_MTU handshake packet leads to crash of bluetooth host layer
- CVE-2024-39815 — Vonets WiFi Bridges Improper Check or Handling of Exceptional Conditions
- CVE-2019-5031 — An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, ver
- CVE-2023-5038 — Unauthenticated DoS
- CVE-2022-22265 — An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary m
- CVE-2024-21525 — All versions of the package node-twain are vulnerable to Improper Check or Handling of Exceptional Conditions due to the
- CVE-2026-20329 — Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software and Secure Firewall Management Center Software Hardening Release - Exceptional Conditions Handling Vulnerabilities