ZeroHour

CVE-2023-35867

CVSS 3.1
5.9 medium
EPSS
<1%p45
Published
()
Modified
Description

An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.

Vendors
bosch
Products
building integration system video engine, bosch video management system, video management system viewer, configuration manager, divar ip 7000 r2 firmware, divar ip all-in-one 4000 firmware, divar ip all-in-one 5000 firmware, divar ip all-in-one 6000 firmware, divar ip all-in-one 7000 firmware, divar ip all-in-one 7000 r3 firmware, intelligent insights, onvif camera event driver tool
Weakness
CWE-703
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.