CVE-2023-35867
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.2 / Impact: 3.6
Source: NVD
Description
An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.
Affected (14)
Products: Bosch: Building Integration System Video Engine, Bosch Video Management System, Video Management System Viewer, Configuration Manager, Divar Ip 7000 R2 Firmware, Divar Ip All In One 4000 Firmware, Divar Ip All In One 5000 Firmware, Divar Ip All In One 6000 Firmware, Divar Ip All In One 7000 Firmware, Divar Ip All In One 7000 R3 Firmware, Intelligent Insights, Onvif Camera Event Driver Tool, Project Assistant, Video Security Client
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.0.1 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 12.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 12.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 7.62 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 12.0 |
| Running on/with | Platform Versions |
|---|---|
Bosch Divar Ip 7000 R2 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 12.0 |
| Running on/with | Platform Versions |
|---|---|
Bosch Divar Ip All In One 4000 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 12.0 |
| Running on/with | Platform Versions |
|---|---|
Bosch Divar Ip All In One 5000 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 12.0 |
| Running on/with | Platform Versions |
|---|---|
Bosch Divar Ip All In One 6000 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 12.0 |
| Running on/with | Platform Versions |
|---|---|
Bosch Divar Ip All In One 7000 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 12.0 |
| Running on/with | Platform Versions |
|---|---|
Bosch Divar Ip All In One 7000 R3 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.0.3.14 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.0.0.8 |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.3 |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.5 |
References (2)
Source: psirt@bosch.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.