5.9
CVSSv3

CVE-2023-35867

Published: 18/12/2023 Updated: 22/12/2023
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 0

Vulnerability Summary

An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated malicious user to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.

Vulnerable Product Search on Vulmon Subscribe to Product

bosch building integration system video engine

bosch bosch video management system

bosch video management system viewer

bosch configuration manager

bosch divar_ip_7000_r2_firmware

bosch divar_ip_all-in-one_4000_firmware

bosch divar_ip_all-in-one_5000_firmware

bosch divar_ip_all-in-one_6000_firmware

bosch divar_ip_all-in-one_7000_firmware

bosch divar_ip_all-in-one_7000_r3_firmware

bosch intelligent insights

bosch onvif camera event driver tool

bosch project assistant

bosch video security client