An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.
References
Link | Resource |
---|---|
https://psirt.bosch.com/security-advisories/BOSCH-SA-092656-BT.html | Vendor Advisory |
https://psirt.bosch.com/security-advisories/BOSCH-SA-092656-BT.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
|
Configuration 12 (hide)
|
Configuration 13 (hide)
|
Configuration 14 (hide)
|
History
21 Nov 2024, 08:08
Type | Values Removed | Values Added |
---|---|---|
References | () https://psirt.bosch.com/security-advisories/BOSCH-SA-092656-BT.html - Vendor Advisory |
22 Dec 2023, 20:13
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-Other | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.9 |
CPE | cpe:2.3:a:bosch:intelligent_insights:*:*:*:*:*:*:*:* cpe:2.3:a:bosch:video_management_system_viewer:*:*:*:*:*:*:*:* cpe:2.3:a:bosch:project_assistant:*:*:*:*:*:*:*:* cpe:2.3:a:bosch:building_integration_system_video_engine:*:*:*:*:*:*:*:* cpe:2.3:h:bosch:divar_ip_all-in-one_7000_r3:-:*:*:*:*:*:*:* cpe:2.3:o:bosch:divar_ip_all-in-one_7000_r3_firmware:*:*:*:*:*:*:*:* cpe:2.3:a:bosch:_onvif_camera_event_driver_tool:*:*:*:*:*:*:*:* cpe:2.3:a:bosch:configuration_manager:*:*:*:*:*:*:*:* cpe:2.3:h:bosch:divar_ip_all-in-one_7000:-:*:*:*:*:*:*:* cpe:2.3:o:bosch:divar_ip_all-in-one_7000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:bosch:divar_ip_all-in-one_5000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:bosch:divar_ip_7000_r2_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:bosch:divar_ip_all-in-one_4000:-:*:*:*:*:*:*:* cpe:2.3:h:bosch:divar_ip_all-in-one_5000:-:*:*:*:*:*:*:* cpe:2.3:a:bosch:video_security_client:*:*:*:*:*:*:*:* cpe:2.3:h:bosch:divar_ip_7000_r2:-:*:*:*:*:*:*:* cpe:2.3:a:bosch:bosch_video_management_system:*:*:*:*:*:*:*:* cpe:2.3:h:bosch:divar_ip_all-in-one_6000:-:*:*:*:*:*:*:* cpe:2.3:o:bosch:divar_ip_all-in-one_6000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:bosch:divar_ip_all-in-one_4000_firmware:*:*:*:*:*:*:*:* |
|
References | () https://psirt.bosch.com/security-advisories/BOSCH-SA-092656-BT.html - Vendor Advisory | |
First Time |
Bosch divar Ip All-in-one 4000 Firmware
Bosch divar Ip All-in-one 6000 Firmware Bosch video Security Client Bosch divar Ip All-in-one 4000 Bosch building Integration System Video Engine Bosch bosch Video Management System Bosch configuration Manager Bosch Onvif Camera Event Driver Tool Bosch divar Ip All-in-one 5000 Bosch Bosch project Assistant Bosch divar Ip 7000 R2 Firmware Bosch video Management System Viewer Bosch divar Ip All-in-one 5000 Firmware Bosch divar Ip All-in-one 7000 Bosch intelligent Insights Bosch divar Ip 7000 R2 Bosch divar Ip All-in-one 7000 R3 Firmware Bosch divar Ip All-in-one 7000 R3 Bosch divar Ip All-in-one 6000 Bosch divar Ip All-in-one 7000 Firmware |
18 Dec 2023, 14:05
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-18 13:15
Updated : 2024-11-21 08:08
NVD link : CVE-2023-35867
Mitre link : CVE-2023-35867
CVE.ORG link : CVE-2023-35867
JSON object : View
Products Affected
bosch
- intelligent_insights
- divar_ip_all-in-one_7000_r3
- video_security_client
- divar_ip_7000_r2
- divar_ip_all-in-one_5000
- project_assistant
- video_management_system_viewer
- bosch_video_management_system
- divar_ip_7000_r2_firmware
- divar_ip_all-in-one_6000
- divar_ip_all-in-one_7000_r3_firmware
- divar_ip_all-in-one_6000_firmware
- divar_ip_all-in-one_5000_firmware
- configuration_manager
- divar_ip_all-in-one_4000_firmware
- divar_ip_all-in-one_7000
- _onvif_camera_event_driver_tool
- divar_ip_all-in-one_4000
- building_integration_system_video_engine
- divar_ip_all-in-one_7000_firmware
CWE