CVE Vulnerabilities

CVE-2021-23861

Active Debug Code

Published: Dec 08, 2021 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

By executing a special command, an user with administrative rights can get access to extended debug functionality on the VRM allowing an impact on integrity or availability of the installed software. This issue also affects installations of the DIVAR IP and BVMS with VRM installed.

Weakness

The product is released with debugging code still enabled or active.

Affected Software

NameVendorStart VersionEnd Version
Bosch_video_management_systemBosch*9.0 (including)
Bosch_video_management_systemBosch10.0 (including)10.0.2 (excluding)
Bosch_video_management_systemBosch10.1 (including)10.1 (including)
Bosch_video_management_systemBosch11.0 (including)11.0 (including)
Video_recording_managerBosch*3.81 (including)
Video_recording_managerBosch3.82 (including)3.82.0057 (including)
Video_recording_managerBosch3.83 (including)3.83.0021 (including)
Video_recording_managerBosch4.0 (including)4.00.0070 (including)

Potential Mitigations

References