PT-2024-20692 · Bosch · Bosch Network Synchronizer

Published

2024-03-25

·

Updated

2024-03-26

·

CVE-2024-25002

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bosch Network Synchronizer (affected versions not specified)
Description Command Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access to the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-25002

Affected Products

Bosch Network Synchronizer