Lucene search

K
nvd[email protected]NVD:CVE-2023-35867
HistoryDec 18, 2023 - 1:15 p.m.

CVE-2023-35867

2023-12-1813:15:07
CWE-703
web.nvd.nist.gov
13
bosch bt
api response packets
dos
mitm attack

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

20.5%

An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.

Affected configurations

Nvd
Node
boschbuilding_integration_system_video_engineRange5.0.1
Node
boschbosch_video_management_systemRange12.0
Node
boschvideo_management_system_viewerRange12.0
Node
boschconfiguration_managerRange7.62
Node
boschdivar_ip_7000_r2_firmwareRange12.0
AND
boschdivar_ip_7000_r2Match-
Node
boschdivar_ip_all-in-one_4000_firmwareRange12.0
AND
boschdivar_ip_all-in-one_4000Match-
Node
boschdivar_ip_all-in-one_5000_firmwareRange12.0
AND
boschdivar_ip_all-in-one_5000Match-
Node
boschdivar_ip_all-in-one_6000_firmwareRange12.0
AND
boschdivar_ip_all-in-one_6000Match-
Node
boschdivar_ip_all-in-one_7000_firmwareRange12.0
AND
boschdivar_ip_all-in-one_7000Match-
Node
boschdivar_ip_all-in-one_7000_r3_firmwareRange12.0
AND
boschdivar_ip_all-in-one_7000_r3Match-
Node
boschintelligent_insightsRange1.0.3.14
Node
bosch_onvif_camera_event_driver_toolRange2.0.0.8
Node
boschproject_assistantRange2.3
Node
boschvideo_security_clientRange3.3.5
VendorProductVersionCPE
boschbuilding_integration_system_video_engine*cpe:2.3:a:bosch:building_integration_system_video_engine:*:*:*:*:*:*:*:*
boschbosch_video_management_system*cpe:2.3:a:bosch:bosch_video_management_system:*:*:*:*:*:*:*:*
boschvideo_management_system_viewer*cpe:2.3:a:bosch:video_management_system_viewer:*:*:*:*:*:*:*:*
boschconfiguration_manager*cpe:2.3:a:bosch:configuration_manager:*:*:*:*:*:*:*:*
boschdivar_ip_7000_r2_firmware*cpe:2.3:o:bosch:divar_ip_7000_r2_firmware:*:*:*:*:*:*:*:*
boschdivar_ip_7000_r2-cpe:2.3:h:bosch:divar_ip_7000_r2:-:*:*:*:*:*:*:*
boschdivar_ip_all-in-one_4000_firmware*cpe:2.3:o:bosch:divar_ip_all-in-one_4000_firmware:*:*:*:*:*:*:*:*
boschdivar_ip_all-in-one_4000-cpe:2.3:h:bosch:divar_ip_all-in-one_4000:-:*:*:*:*:*:*:*
boschdivar_ip_all-in-one_5000_firmware*cpe:2.3:o:bosch:divar_ip_all-in-one_5000_firmware:*:*:*:*:*:*:*:*
boschdivar_ip_all-in-one_5000-cpe:2.3:h:bosch:divar_ip_all-in-one_5000:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 201

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

20.5%

Related for NVD:CVE-2023-35867