First published: Wed Jun 22 2022(Updated: )
The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command injection through its diagnostics web interface. This allows execution of shell commands.
Credit: psirt@bosch.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bosch Pra-es8p2s Firmware | <=1.01.05 | |
Bosch Pra-es8p2s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32534 is a vulnerability in the Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier that allows command injection through its diagnostics web interface.
CVE-2022-32534 has a severity score of 9.8, which is considered critical.
The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier is affected by CVE-2022-32534.
CVE-2022-32534 can be exploited by executing malicious shell commands through the switch's diagnostics web interface.
Yes, Bosch has released a security advisory with mitigation measures for CVE-2022-32534. Please refer to the reference link for more information.