An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Bosch
Subscribe
|
Onvif Camera Event Driver Tool
Subscribe
Bosch Video Management System
Subscribe
Building Integration System Video Engine
Subscribe
Configuration Manager
Subscribe
Divar Ip 7000 R2
Subscribe
Divar Ip 7000 R2 Firmware
Subscribe
Divar Ip All-in-one 4000
Subscribe
Divar Ip All-in-one 4000 Firmware
Subscribe
Divar Ip All-in-one 5000
Subscribe
Divar Ip All-in-one 5000 Firmware
Subscribe
Divar Ip All-in-one 6000
Subscribe
Divar Ip All-in-one 6000 Firmware
Subscribe
Divar Ip All-in-one 7000
Subscribe
Divar Ip All-in-one 7000 Firmware
Subscribe
Divar Ip All-in-one 7000 R3
Subscribe
Divar Ip All-in-one 7000 R3 Firmware
Subscribe
Intelligent Insights
Subscribe
Project Assistant
Subscribe
Video Management System Viewer
Subscribe
Video Security Client
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-39860 | An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: bosch
Published:
Updated: 2024-08-02T16:30:45.391Z
Reserved: 2023-06-19T09:15:32.387Z
Link: CVE-2023-35867
No data.
Status : Modified
Published: 2023-12-18T13:15:07.010
Modified: 2024-11-21T08:08:51.793
Link: CVE-2023-35867
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD