9
CVE-2022-32536
- EPSS 1.02%
- Veröffentlicht 23.06.2022 17:15:13
- Zuletzt bearbeitet 21.11.2024 07:06:35
- CVE-Watchlists
- Unerledigt
Privilege Escalation
The user access rights validation in the web server of the Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 was insufficient. This would allow a non-administrator user to obtain administrator user access rights.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bosch ≫ Pra-es8p2s Firmware Version <= 1.01.05
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.02% | 0.604 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 9 | 8 | 10 |
AV:N/AC:L/Au:S/C:C/I:C/A:C
|
| Bosch | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
https://psirt.bosch.com/security-advisories/BOSCH-SA-247052-BT.html