CVE-2022-32534 is a critical command injection vulnerability affecting Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier, allowing attackers to execute arbitrary shell commands via the diagnostics web interface. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network without authentication or user interaction, leading to complete compromise of confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, the high severity warrants immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.01.05CPE matchmatch criteria | cpe:2.3:o:bosch:pra-es8p2s_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple Vulnerabilities PRA-ES8P2S Ethernet-Switch
Jun 22, 2022Multiple Vulnerabilities PRA-ES8P2S Ethernet-Switch
Jun 22, 2022Multiple Vulnerabilities PRA-ES8P2S Ethernet-Switch
Jun 22, 2022Multiple Vulnerabilities PRA-ES8P2S Ethernet-Switch
Jun 22, 2022Multiple Vulnerabilities PRA-ES8P2S Ethernet-Switch
Jun 22, 2022Multiple Vulnerabilities PRA-ES8P2S Ethernet-Switch
Jun 22, 2022