PT-2022-3473 · Bosch · Bosch Pra-Es8P2S

Published

2022-06-07

·

Updated

2023-06-29

·

CVE-2022-32534

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Bosch PRA-ES8P2S versions 1.01.05 and earlier
Description The issue is related to insufficient input validation in the diagnostics web interface of the Bosch PRA-ES8P2S Ethernet switch. This allows a remote attacker to execute arbitrary operating system commands using specially crafted data. The vulnerability can be exploited through the diagnostics web interface, enabling the execution of shell commands.
Recommendations For versions 1.01.05 and earlier, consider disabling the diagnostics web interface as a temporary workaround until a patch is available. Restrict access to the web interface to minimize the risk of exploitation.

Fix

OS Command Injection

RCE

Weakness Enumeration

Related Identifiers

BDU:2022-04252
CVE-2022-32534

Affected Products

Bosch Pra-Es8P2S