PT-2024-13785 · Bosch · Bcc101+3

Published

2024-01-09

·

Updated

2024-01-17

·

CVE-2023-49722

CVSS v3.1

8.3

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bosch BCC100 smart thermostat (affected versions not specified) BCC101/BCC102/BCC50 products (affected versions not specified)
Description A vulnerability allows an unauthenticated attacker to replace the device’s firmware with a malicious one by connecting to the device via the same WiFi network. This is possible due to an open debug port 8899 in the WiFi firmware. An attacker could potentially install a backdoor in the thermostat, use it to sniff traffic, or pivot onto other devices. The issue is related to the open network port 8899.
Recommendations For BCC101/BCC102/BCC50 products, consider disabling access to network port 8899 until a patch is available. For Bosch BCC100 smart thermostat, update to firmware v4.13.33 for enhanced security. As a temporary workaround, consider restricting access to the device via the same WiFi network to minimize the risk of exploitation. Restrict access to the open debug port 8899 to prevent potential attacks.

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-49722

Affected Products

Bcc101
Bcc102
Bcc50
Bosch Bcc100