A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or change settings of the camera by sending crafted requests to the device. Only devices of the CPP6, CPP7 and CPP7.3 family with firmware 7.70, 7.72, and 7.80 prior to B128 are affected by this vulnerability. Versions 7.62 or lower and INTEOX cameras are not affected.
Conclusion & alert: CVE-2021-23847 is rated Moderate Risk (61.5/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.46%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-01-29 | 0.34% | 0.46% | +0.12% |
| 2 | 2025-11-21 | 0.36% | 0.34% | -0.02% |
| 3 | 2025-11-18 | — | 0.36% | — |
Full EPSS history (14 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 9.1 | 3.1 | CRITICAL |
|
3.9 | 5.2 | [email protected] |
| 6.4 | 2.0 | MEDIUM |
|
10.0 | 4.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| bosch | cpp6_firmware | >= 7.80, < 7.80.0129 | cpe:2.3:o:bosch:cpp6_firmware:*:*:*:*:*:*:*:* |
| bosch | cpp6_firmware | 7.70 | cpe:2.3:o:bosch:cpp6_firmware:7.70:*:*:*:*:*:*:* |
| bosch | cpp6_firmware | 7.72 | cpe:2.3:o:bosch:cpp6_firmware:7.72:*:*:*:*:*:*:* |
| bosch | cpp7_firmware | >= 7.80, < 7.80.0129 | cpe:2.3:o:bosch:cpp7_firmware:*:*:*:*:*:*:*:* |
| bosch | cpp7_firmware | 7.70 | cpe:2.3:o:bosch:cpp7_firmware:7.70:*:*:*:*:*:*:* |
| bosch | cpp7_firmware | 7.72 | cpe:2.3:o:bosch:cpp7_firmware:7.72:*:*:*:*:*:*:* |
| bosch | cpp7.3_firmware | >= 7.80, < 7.80.0129 | cpe:2.3:o:bosch:cpp7.3_firmware:*:*:*:*:*:*:*:* |
| bosch | cpp7.3_firmware | 7.70 | cpe:2.3:o:bosch:cpp7.3_firmware:7.70:*:*:*:*:*:*:* |
| bosch | cpp7.3_firmware | 7.72 | cpe:2.3:o:bosch:cpp7.3_firmware:7.72:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://psirt.bosch.com/security-advisories/bosch-sa-478243-bt.html | Vendor Advisory |