Loading HuntDB...

GHSA-w9fc-5fg9-fgph

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM installation this crash also opens the possibility to send further unauthenticated commands to the service. On some products the interface is only local accessible lowering the CVSS base score. For a list of modified CVSS scores, please see the official Bosch Advisory Appendix chapter Modified CVSS Scores for CVE-2021-23859

Related CVEs

Key Information

GHSA ID
GHSA-w9fc-5fg9-fgph
Published
December 9, 2021 12:00 AM
Last Modified
December 15, 2021 12:01 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 6, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.