CVE-2021-23862

A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in system context. This issue also affects installations of the VRM, DIVAR IP, BVMS with VRM installed, the VIDEOJET decoder (VJD-7513 and VJD-8000).
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:bosch:bosch_video_management_system:*:*:*:*:*:*:*:*
cpe:2.3:a:bosch:video_recording_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:bosch:video_recording_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:bosch:video_recording_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:bosch:bosch_video_management_system:11.0:*:*:*:*:*:*:*
cpe:2.3:a:bosch:bosch_video_management_system:*:*:*:*:*:*:*:*
cpe:2.3:a:bosch:bosch_video_management_system:10.1:*:*:*:*:*:*:*
cpe:2.3:a:bosch:video_recording_manager:*:*:*:*:*:*:*:*
OR cpe:2.3:o:bosch:divar_ip_7000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:bosch:divar_ip_5000_firmware:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:bosch:videojet_decoder_7513_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:bosch:videojet_decoder_7513:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:bosch:videojet_decoder_8000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:bosch:videojet_decoder_8000:-:*:*:*:*:*:*:*

Information

Published : 2021-12-08 14:15

Updated : 2022-08-30 11:34


NVD link : CVE-2021-23862

Mitre link : CVE-2021-23862


JSON object : View

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Advertisement

dedicated server usa

Products Affected

bosch

  • videojet_decoder_8000
  • videojet_decoder_7513
  • videojet_decoder_8000_firmware
  • divar_ip_7000_firmware
  • bosch_video_management_system
  • videojet_decoder_7513_firmware
  • divar_ip_5000_firmware
  • video_recording_manager