CVE detail
CVE-2021-23859 — CVE-2021-23859
Published 2021-12-08 · Modified 2026-06-17 · Vendor bosch · Product bosch_video_management_system · Source nvd
CRITICAL
severity
CVSS-derived band
0.0097
EPSS probability
exploitation probability, 30d
59.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM installation this crash also opens the possibility to send further unauthenticated commands to the service. On some products the interface is only local accessible lowering the CVSS base score. For a list of modified CVSS scores, please see the official Bosch Advisory Appendix chapter Modified CVSS Scores for CVE-2021-23859
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References