5.9

CVE-2023-35867

An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BoschConfiguration Manager Version <= 7.62
BoschDivar Ip 7000 R2 Firmware Version <= 12.0
   BoschDivar Ip 7000 R2 Version-
BoschIntelligent Insights Version <= 1.0.3.14
Bosch Onvif Camera Event Driver Tool Version <= 2.0.0.8
BoschProject Assistant Version <= 2.3
BoschVideo Security Client Version <= 3.3.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.08% 0.246
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
psirt@bosch.com 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-703 Improper Check or Handling of Exceptional Conditions

The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.