CVE-2023-35867: Medium severity bosch building integration system video engine vulnerability
An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-35867?
CVE-2023-35867 is classified as a moderate severity vulnerability due to its potential for causing Denial of Service (DoS).
How do I fix CVE-2023-35867?
To mitigate CVE-2023-35867, users should update their Bosch software products to the latest versions that have addressed this vulnerability.
What products are affected by CVE-2023-35867?
CVE-2023-35867 affects various Bosch products including versions of the Bosch Building Integration System Video Engine, Bosch Video Management System, and several Divar IP firmware versions.
Can CVE-2023-35867 be exploited remotely?
Yes, CVE-2023-35867 can be exploited by unauthenticated attackers who can perform a Man-in-the-Middle attack to deliver malformed API packets.
What type of attack does CVE-2023-35867 facilitate?
CVE-2023-35867 facilitates a Denial of Service (DoS) attack that disrupts the availability of affected Bosch services.