PT-2022-6306 · Bosch · Bosch B420

Published

2022-12-21

·

Updated

2023-08-08

·

CVE-2022-47648

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bosch B420 firmware 02.02.0001
Description The issue is related to improper access control in the Bosch B420 Ethernet module's control panel, allowing an attacker to bypass security restrictions and gain unauthorized access to protected information by sending specially crafted requests. This is due to the use of IP-based authorization in the authentication mechanism, which enables attackers to access the device if they are on the same network as a legitimate user. The B420 module is obsolete, with its End of Life announcement made in 2013.
Recommendations For Bosch B420 firmware 02.02.0001, consider restricting access to the control panel to minimize the risk of exploitation, as the device's IP-based authorization mechanism can be bypassed by attackers on the same network as a legitimate user. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Improper Authentication

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

BDU:2023-00801
CVE-2022-47648

Affected Products

Bosch B420