CVE-2022-32534: OS Command Injection
The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command injection through its diagnostics web interface. This allows execution of shell commands.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-32534?
CVE-2022-32534 is a vulnerability in the Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier that allows command injection through its diagnostics web interface.
How severe is CVE-2022-32534?
CVE-2022-32534 has a severity score of 9.8, which is considered critical.
What is affected by CVE-2022-32534?
The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier is affected by CVE-2022-32534.
How can CVE-2022-32534 be exploited?
CVE-2022-32534 can be exploited by executing malicious shell commands through the switch's diagnostics web interface.
Is there a fix for CVE-2022-32534?
Yes, Bosch has released a security advisory with mitigation measures for CVE-2022-32534. Please refer to the reference link for more information.