Medium severity5.9NVD Advisory· Published Dec 18, 2023· Updated Jun 17, 2026
CVE-2023-35867
CVE-2023-35867
Description
An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18- cpe:2.3:a:bosch:_onvif_camera_event_driver_tool:*:*:*:*:*:*:*:*Range: <=2.0.0.8
- cpe:2.3:a:bosch:bosch_video_management_system:*:*:*:*:*:*:*:*Range: <=12.0
- cpe:2.3:a:bosch:building_integration_system_video_engine:*:*:*:*:*:*:*:*Range: <=5.0.1
cpe:2.3:a:bosch:configuration_manager:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:bosch:configuration_manager:*:*:*:*:*:*:*:*range: <=7.62
- (no CPE)range: 0
- cpe:2.3:a:bosch:video_management_system_viewer:*:*:*:*:*:*:*:*Range: <=12.0
- cpe:2.3:o:bosch:divar_ip_7000_r2_firmware:*:*:*:*:*:*:*:*Range: <=12.0
- cpe:2.3:o:bosch:divar_ip_all-in-one_4000_firmware:*:*:*:*:*:*:*:*Range: <=12.0
- cpe:2.3:o:bosch:divar_ip_all-in-one_5000_firmware:*:*:*:*:*:*:*:*Range: <=12.0
- cpe:2.3:o:bosch:divar_ip_all-in-one_6000_firmware:*:*:*:*:*:*:*:*Range: <=12.0
- cpe:2.3:o:bosch:divar_ip_all-in-one_7000_firmware:*:*:*:*:*:*:*:*Range: <=12.0
- cpe:2.3:o:bosch:divar_ip_all-in-one_7000_r3_firmware:*:*:*:*:*:*:*:*Range: <=12.0
- Range: 0
- Range: 0
Patches
Vulnerability mechanics
References
1- psirt.bosch.com/security-advisories/BOSCH-SA-092656-BT.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.