An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firmware before 6.52.4. A malicious client could potentially succeed in the unauthorized execution of code on the device via the network interface, because there is a buffer overflow in the RCP+ parser of the web server.
References
Link | Resource |
---|---|
https://psirt.bosch.com/Advisory/BOSCH-2018-1203.html | Mitigation Vendor Advisory |
Information
Published : 2018-12-19 14:29
Updated : 2021-09-09 06:15
NVD link : CVE-2018-20299
Mitre link : CVE-2018-20299
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
bosch
- 360-indoor_camera_firmware
- 360-indoor_camera
- eyes_outdoor_camera_firmware
- eyes_outdoor_camera