Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2021-23843
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Lack of authentication mechanisms on the device
Source: NVD (National Vulnerability Database)
Vulnerability Description
The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a password protection on configured devices to restrict access to the configuration of an AMC2. An attacker can circumvent this protection and make unauthorized changes to configuration data on the device. An attacker can exploit this vulnerability to manipulate the device\'s configuration or make it unresponsive in the local network. The attacker needs to have access to the local network, typically even the same subnet.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
关键功能的认证机制缺失
Source: NVD (National Vulnerability Database)
Vulnerability Title
Bosch Amc2 访问控制错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Bosch Amc2是德国Bosch公司的一个访问模块化控制器。 Bosch AMC2 存在访问控制错误漏洞,该漏洞源于 Bosch software tools AccessIPConfig.exe 和 AmcIpConfig.exe 用于配置 AMC2 设备中的某些设置。 该工具允许在配置的设备上设置密码保护,以限制对 AMC2 配置的访问。 攻击者可以绕过这种保护并对设备上的配置数据进行未经授权的更改。 攻击者可以利用此漏洞来操纵设备的配置或使其在本地网络中无响应。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
BoschAMS unspecified ~ 4.0 -
BoschAPE unspecified ~ 3.8.x -
BoschBIS unspecified ~ 4.9.1 -
BoschAMC2 all -
II. Public POCs for CVE-2021-23843
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2021-23843
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2021-23843

No comments yet


Leave a comment