CVE-2023-35867
18.12.2023, 13:15
An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.Enginsight
Vendor | Product | Version |
---|---|---|
bosch | building_integration_system_video_engine | 𝑥 ≤ 5.0.1 |
bosch | bosch_video_management_system | 𝑥 ≤ 12.0 |
bosch | video_management_system_viewer | 𝑥 ≤ 12.0 |
bosch | configuration_manager | 𝑥 ≤ 7.62 |
bosch | divar_ip_7000_r2_firmware | 𝑥 ≤ 12.0 |
bosch | divar_ip_all-in-one_4000_firmware | 𝑥 ≤ 12.0 |
bosch | divar_ip_all-in-one_5000_firmware | 𝑥 ≤ 12.0 |
bosch | divar_ip_all-in-one_6000_firmware | 𝑥 ≤ 12.0 |
bosch | divar_ip_all-in-one_7000_firmware | 𝑥 ≤ 12.0 |
bosch | divar_ip_all-in-one_7000_r3_firmware | 𝑥 ≤ 12.0 |
bosch | intelligent_insights | 𝑥 ≤ 1.0.3.14 |
bosch | _onvif_camera_event_driver_tool | 𝑥 ≤ 2.0.0.8 |
bosch | project_assistant | 𝑥 ≤ 2.3 |
bosch | video_security_client | 𝑥 ≤ 3.3.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration