CVE-2023-35867: Bosch Onvif Camera Event Driver Tool

Medium severity, CVSS 5.9. EPSS: 0.6% chance of exploitation in the next 30 days.

An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.

Affected products

  • Bosch Onvif Camera Event Driver Tool: up to and including 2.0.0.8
  • Bosch Bosch Video Management System: up to and including 12.0
  • Bosch Building Integration System Video Engine: up to and including 5.0.1
  • Bosch Configuration Manager: up to and including 7.62
  • Bosch Divar IP 7000 r2 Firmware: up to and including 12.0
  • Bosch Divar IP All-In-One 4000 Firmware: up to and including 12.0
  • Bosch Divar IP All-In-One 5000 Firmware: up to and including 12.0
  • Bosch Divar IP All-In-One 6000 Firmware: up to and including 12.0
  • Bosch Divar IP All-In-One 7000 Firmware: up to and including 12.0
  • Bosch Divar IP All-In-One 7000 r3 Firmware: up to and including 12.0
  • Bosch Intelligent Insights: up to and including 1.0.3.14
  • Bosch Project Assistant: up to and including 2.3
  • Bosch Video Management System Viewer: up to and including 12.0
  • Bosch Video Security Client: up to and including 3.3.5

Published 2023-12-18. Last modified 2026-06-17.