Lucene search

K
cve[email protected]CVE-2021-23843
HistoryJan 19, 2022 - 9:15 p.m.

CVE-2021-23843

2022-01-1921:15:08
CWE-306
web.nvd.nist.gov
30
bosch
software
tools
accessipconfig.exe
amcipconfig.exe
vulnerability
amc2 devices
unauthorized changes
local network
nvd
cve-2021-23843

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

8.8 High

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.6%

The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a password protection on configured devices to restrict access to the configuration of an AMC2. An attacker can circumvent this protection and make unauthorized changes to configuration data on the device. An attacker can exploit this vulnerability to manipulate the device's configuration or make it unresponsive in the local network. The attacker needs to have access to the local network, typically even the same subnet.

Affected configurations

NVD
Node
boschamc2_firmwareMatch-
AND
boschamc2Match-
Node
boschaccess_management_systemMatch3.0
Node
boschaccess_professional_editionRange3.8.0
Node
boschbuilding_integration_systemRange<4.9.1

CNA Affected

[
  {
    "product": "AMS",
    "vendor": "Bosch",
    "versions": [
      {
        "lessThan": "4.0",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "APE",
    "vendor": "Bosch",
    "versions": [
      {
        "lessThanOrEqual": "3.8.x",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "BIS",
    "vendor": "Bosch",
    "versions": [
      {
        "lessThan": "4.9.1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "AMC2",
    "vendor": "Bosch",
    "versions": [
      {
        "status": "affected",
        "version": "all"
      }
    ]
  }
]

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

8.8 High

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

7.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.6%

Related for CVE-2021-23843