CVE-2023-35867
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/12/2023
Last modified:
22/12/2023
Description
An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.
Impact
Base Score 3.x
5.90
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:bosch:building_integration_system_video_engine:*:*:*:*:*:*:*:* | 5.0.1 (including) | |
cpe:2.3:a:bosch:bosch_video_management_system:*:*:*:*:*:*:*:* | 12.0 (including) | |
cpe:2.3:a:bosch:video_management_system_viewer:*:*:*:*:*:*:*:* | 12.0 (including) | |
cpe:2.3:a:bosch:configuration_manager:*:*:*:*:*:*:*:* | 7.62 (including) | |
cpe:2.3:o:bosch:divar_ip_7000_r2_firmware:*:*:*:*:*:*:*:* | 12.0 (including) | |
cpe:2.3:h:bosch:divar_ip_7000_r2:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:bosch:divar_ip_all-in-one_4000_firmware:*:*:*:*:*:*:*:* | 12.0 (including) | |
cpe:2.3:h:bosch:divar_ip_all-in-one_4000:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:bosch:divar_ip_all-in-one_5000_firmware:*:*:*:*:*:*:*:* | 12.0 (including) | |
cpe:2.3:h:bosch:divar_ip_all-in-one_5000:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:bosch:divar_ip_all-in-one_6000_firmware:*:*:*:*:*:*:*:* | 12.0 (including) | |
cpe:2.3:h:bosch:divar_ip_all-in-one_6000:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:bosch:divar_ip_all-in-one_7000_firmware:*:*:*:*:*:*:*:* | 12.0 (including) | |
cpe:2.3:h:bosch:divar_ip_all-in-one_7000:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:bosch:divar_ip_all-in-one_7000_r3_firmware:*:*:*:*:*:*:*:* | 12.0 (including) |
To consult the complete list of CPE names with products and versions, see this page