CVE Database
/

CVE-2023-35867

Back to search

CVE-2023-35867

Published: Dec 18, 2023

Modified: Aug 2, 2024

PUBLISHED

CVSS v3.1

5.9

MEDIUM

Description

An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.

VendorProductVersions

Bosch

BVMS

affected
0 - <= 12.0.0

Bosch

BVMS Viewer

affected
0 - <= 12.0.0

Bosch

Configuration Manager

affected
0 - <= 7.62

Bosch

DIVAR IP 7000 R2

affected
0 - <= 12.0.0

Bosch

DIVAR IP all-in-one 5000

affected
0 - <= 12.0.0

Bosch

DIVAR IP all-in-one 7000

affected
0 - <= 12.0.0

Bosch

DIVAR IP all-in-one 7000 R3

affected
0 - <= 12.0.0

Bosch

DIVAR IP all-in-one 4000

affected
0 - <= 12.0.0

Bosch

DIVAR IP all-in-one 6000

affected
0 - <= 12.0.0

Bosch

Project Assistant

affected
0 - <= 2.3

Bosch

Video Security Client

affected
0 - <= 3.3.5

Bosch

BIS Video Engine

affected
0 - <= 5.0.1

Bosch

Intelligent Insights

affected
0 - <= 1.0.3.14

Bosch

ONVIF Camera Event Driver Tool

affected
0 - <= 2.0.0.8

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Network

Attack Complexity

High

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now