CVE-2023-32229 Vulnerability Details

  /     /     /  

CVE-2023-32229 Metadata Quick Info

CVE Published: 15/06/2023 | CVE Updated: 02/08/2024 | CVE Year: 2023
Source: bosch | Vendor: Bosch | Product: Camera Firmware
Status : PUBLISHED

CVE-2023-32229 Description

Due to an error in the software interface to the secure element chip on Bosch IP cameras of family CPP13 and CPP14, the chip can be permanently damaged when enabling the Stream security option (signing of the video stream) with option MD5, SHA-1 or SHA-256.

Metrics

CVSS Version: 3.1 | Base Score: 4.9 MEDIUM
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* HIGH
    User Interaction (UI)* NONE
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* NONE
    Integrity Impact (I)* NONE
    Availability Impact (A)* HIGH

Weakness Enumeration (CWE)

CWE-ID: CWE-1246
CWE Name: CWE-1246 Improper Write Handling in Limited-write Non-Volatile Memories
Source: Bosch

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).