CVE-2023-35867: Bosch Onvif Camera Event Driver Tool
Medium severity, CVSS 5.9. EPSS: 0.6% chance of exploitation in the next 30 days.
An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.
Affected products
- Bosch Onvif Camera Event Driver Tool: up to and including 2.0.0.8
- Bosch Bosch Video Management System: up to and including 12.0
- Bosch Building Integration System Video Engine: up to and including 5.0.1
- Bosch Configuration Manager: up to and including 7.62
- Bosch Divar IP 7000 r2 Firmware: up to and including 12.0
- Bosch Divar IP All-In-One 4000 Firmware: up to and including 12.0
- Bosch Divar IP All-In-One 5000 Firmware: up to and including 12.0
- Bosch Divar IP All-In-One 6000 Firmware: up to and including 12.0
- Bosch Divar IP All-In-One 7000 Firmware: up to and including 12.0
- Bosch Divar IP All-In-One 7000 r3 Firmware: up to and including 12.0
- Bosch Intelligent Insights: up to and including 1.0.3.14
- Bosch Project Assistant: up to and including 2.3
- Bosch Video Management System Viewer: up to and including 12.0
- Bosch Video Security Client: up to and including 3.3.5
Published 2023-12-18. Last modified 2026-06-17.