CVE-2022-32535: Web server runs as root
The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 runs its web server with root privilege. In combination with CVE-2022-23534 this could give an attacker root access to the switch.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-32535?
CVE-2022-32535 is a vulnerability that allows an attacker to gain root access to the Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 by exploiting the web server running with root privilege.
How severe is CVE-2022-32535?
CVE-2022-32535 has a severity rating of 9.8 (critical).
What software versions are affected by CVE-2022-32535?
Software version 1.01.05 of the Bosch Ethernet switch PRA-ES8P2S is affected by CVE-2022-32535.
How can an attacker exploit CVE-2022-32535?
An attacker can exploit CVE-2022-32535 by leveraging the root privilege of the web server running on the Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05.
Is CVE-2022-32535 related to any other vulnerabilities?
CVE-2022-32535 is related to CVE-2022-23534, which in combination can give an attacker root access to the Bosch Ethernet switch PRA-ES8P2S.