First published: Wed Jun 22 2022(Updated: )
The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 runs its web server with root privilege. In combination with CVE-2022-23534 this could give an attacker root access to the switch.
Credit: psirt@bosch.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bosch Pra-es8p2s Firmware | <=1.01.05 | |
Bosch Pra-es8p2s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32535 is a vulnerability that allows an attacker to gain root access to the Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 by exploiting the web server running with root privilege.
CVE-2022-32535 has a severity rating of 9.8 (critical).
Software version 1.01.05 of the Bosch Ethernet switch PRA-ES8P2S is affected by CVE-2022-32535.
An attacker can exploit CVE-2022-32535 by leveraging the root privilege of the web server running on the Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05.
CVE-2022-32535 is related to CVE-2022-23534, which in combination can give an attacker root access to the Bosch Ethernet switch PRA-ES8P2S.