{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-35867","assignerOrgId":"c95f66b2-7e7c-41c5-8f09-6f86ec68659c","state":"PUBLISHED","assignerShortName":"bosch","dateReserved":"2023-06-19T09:15:32.387Z","datePublished":"2023-12-18T12:59:48.604Z","dateUpdated":"2024-08-02T16:30:45.391Z"},"containers":{"cna":{"providerMetadata":{"orgId":"c95f66b2-7e7c-41c5-8f09-6f86ec68659c","shortName":"bosch","dateUpdated":"2023-12-18T12:59:48.604Z"},"descriptions":[{"lang":"en","value":"An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks."}],"affected":[{"vendor":"Bosch","product":"BVMS","versions":[{"version":"0","status":"affected","versionType":"custom","lessThanOrEqual":"12.0.0"}]},{"vendor":"Bosch","product":"BVMS Viewer","versions":[{"version":"0","status":"affected","versionType":"custom","lessThanOrEqual":"12.0.0"}]},{"vendor":"Bosch","product":"Configuration Manager","versions":[{"version":"0","status":"affected","versionType":"custom","lessThanOrEqual":"7.62"}]},{"vendor":"Bosch","product":"DIVAR IP 7000 R2","versions":[{"version":"0","status":"affected","versionType":"custom","lessThanOrEqual":"12.0.0"}]},{"vendor":"Bosch","product":"DIVAR IP all-in-one 5000","versions":[{"version":"0","status":"affected","versionType":"custom","lessThanOrEqual":"12.0.0"}]},{"vendor":"Bosch","product":"DIVAR IP all-in-one 7000","versions":[{"version":"0","status":"affected","versionType":"custom","lessThanOrEqual":"12.0.0"}]},{"vendor":"Bosch","product":"DIVAR IP all-in-one 7000 R3","versions":[{"version":"0","status":"affected","versionType":"custom","lessThanOrEqual":"12.0.0"}]},{"vendor":"Bosch","product":"DIVAR IP all-in-one 4000","versions":[{"version":"0","status":"affected","versionType":"custom","lessThanOrEqual":"12.0.0"}]},{"vendor":"Bosch","product":"DIVAR IP all-in-one 6000","versions":[{"version":"0","status":"affected","versionType":"custom","lessThanOrEqual":"12.0.0"}]},{"vendor":"Bosch","product":"Project Assistant","versions":[{"version":"0","status":"affected","versionType":"custom","lessThanOrEqual":"2.3"}]},{"vendor":"Bosch","product":"Video Security Client","versions":[{"version":"0","status":"affected","versionType":"custom","lessThanOrEqual":"3.3.5"}]},{"vendor":"Bosch","product":"BIS Video Engine","versions":[{"version":"0","status":"affected","versionType":"custom","lessThanOrEqual":"5.0.1"}]},{"vendor":"Bosch","product":"Intelligent Insights","versions":[{"version":"0","status":"affected","versionType":"custom","lessThanOrEqual":"1.0.3.14"}]},{"vendor":"Bosch","product":"ONVIF Camera Event Driver Tool","versions":[{"version":"0","status":"affected","versionType":"custom","lessThanOrEqual":"2.0.0.8"}]}],"problemTypes":[{"descriptions":[{"lang":"en-US","description":"CWE-703 Improper Check or Handling of Exceptional Conditions","cweId":"CWE-703"}]}],"references":[{"url":"https://psirt.bosch.com/security-advisories/BOSCH-SA-092656-BT.html","name":"https://psirt.bosch.com/security-advisories/BOSCH-SA-092656-BT.html","tags":["vendor-advisory"]}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T16:30:45.391Z"},"title":"CVE Program Container","references":[{"url":"https://psirt.bosch.com/security-advisories/BOSCH-SA-092656-BT.html","name":"https://psirt.bosch.com/security-advisories/BOSCH-SA-092656-BT.html","tags":["vendor-advisory","x_transferred"]}]}]}}