CVE-2023-35867

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/12/2023
Last modified:
22/12/2023

Description

An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bosch:building_integration_system_video_engine:*:*:*:*:*:*:*:* 5.0.1 (including)
cpe:2.3:a:bosch:bosch_video_management_system:*:*:*:*:*:*:*:* 12.0 (including)
cpe:2.3:a:bosch:video_management_system_viewer:*:*:*:*:*:*:*:* 12.0 (including)
cpe:2.3:a:bosch:configuration_manager:*:*:*:*:*:*:*:* 7.62 (including)
cpe:2.3:o:bosch:divar_ip_7000_r2_firmware:*:*:*:*:*:*:*:* 12.0 (including)
cpe:2.3:h:bosch:divar_ip_7000_r2:-:*:*:*:*:*:*:*
cpe:2.3:o:bosch:divar_ip_all-in-one_4000_firmware:*:*:*:*:*:*:*:* 12.0 (including)
cpe:2.3:h:bosch:divar_ip_all-in-one_4000:-:*:*:*:*:*:*:*
cpe:2.3:o:bosch:divar_ip_all-in-one_5000_firmware:*:*:*:*:*:*:*:* 12.0 (including)
cpe:2.3:h:bosch:divar_ip_all-in-one_5000:-:*:*:*:*:*:*:*
cpe:2.3:o:bosch:divar_ip_all-in-one_6000_firmware:*:*:*:*:*:*:*:* 12.0 (including)
cpe:2.3:h:bosch:divar_ip_all-in-one_6000:-:*:*:*:*:*:*:*
cpe:2.3:o:bosch:divar_ip_all-in-one_7000_firmware:*:*:*:*:*:*:*:* 12.0 (including)
cpe:2.3:h:bosch:divar_ip_all-in-one_7000:-:*:*:*:*:*:*:*
cpe:2.3:o:bosch:divar_ip_all-in-one_7000_r3_firmware:*:*:*:*:*:*:*:* 12.0 (including)


References to Advisories, Solutions, and Tools