CVE-2022-36301: Critical severity bosch bf-os vulnerability
Published Aug 1, 2022
·Updated
BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device password.
Affected Software
1 affected component
Bosch Bf-os>=3.0<=3.83
Event History
Aug 1, 2022
CVE Published
via MITRE·02:02 PM
Data Sourced
via MITRE·02:02 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-36301.
2
What is the severity of CVE-2022-36301?
The severity of CVE-2022-36301 is critical with a CVSS score of 7.5.
3
What is the affected software?
The affected software is BF-OS version 3.x up to and including 3.83.
4
What is the impact of this vulnerability?
This vulnerability may allow a remote attacker to brute-force the device password.
5
Are there any patches or fixes available for CVE-2022-36301?
Please refer to the vendor's security advisory at https://psirt.bosch.com/security-advisories/bosch-sa-013924-bt.html for information on patches or fixes.