PT-2022-3526 · Bosch · Bosch Ethernet Switch Pra-Es8P2S

Published

2022-06-07

·

Updated

2022-07-01

·

CVE-2022-32535

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Bosch Ethernet switch PRA-ES8P2S version 1.01.05
Description The issue is related to insufficient access control in the software of the Bosch Ethernet switch PRA-ES8P2S. This could allow a remote attacker to bypass existing security restrictions and gain elevated privileges, potentially up to root level. The web server of the switch runs with root privilege, which could be exploited to gain root access.
Recommendations For version 1.01.05, consider restricting access to the web server or disabling it until a patch is available to prevent potential exploitation. Additionally, review and implement strict access controls to minimize the risk of privilege escalation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04309
CVE-2022-32535

Affected Products

Bosch Ethernet Switch Pra-Es8P2S