Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-47648

26
FAUCET Score

CVE-2022-47648 is an Improper Access Control vulnerability affecting the obsolete Bosch B420 module and its firmware. It allows an unauthenticated attacker on the same network to gain full access to the control panel if an authorized user has previously accessed it. This vulnerability carries a high CVSS score of 8.8, indicating a severe risk with high impact on confidentiality, integrity, and availability, requiring no user interaction or privileges. Despite its high severity, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
02.02.0001CPE matchmatch criteria
cpe:2.3:o:bosch:b420_firmware:02.02.0001:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.6HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.43%
Probability of exploitation in next 30 days
EPSS Percentile
34.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0043 is in the 32nd percentile among its peer group of 1,859 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

chainsafevendor investigatingvia llm_extracted
gogsvendor investigatingvia llm_extracted
openpgpjsvendor investigatingvia llm_extracted
opensslvendor investigatingvia llm_extracted

Vendor Advisories (4)

openpgpjsllm-openpgpjs-5ec007920367aed9HIGH

Insecure authentication in B420 legacy communication module

Apr 26, 2023
opensslllm-openssl-c037f70d5fb6dac7HIGH

Insecure authentication in B420 legacy communication module

Apr 26, 2023
gogsllm-gogs-97b73cb7bf70cfd9HIGH

Insecure authentication in B420 legacy communication module

Apr 26, 2023
chainsafellm-chainsafe-d709c43c536c299eHIGH

Insecure authentication in B420 legacy communication module

Apr 26, 2023

References

drive.google.com / drive/folders/16jvVFyp9RlHvXvq7qbOCjCs1jiAPT3i_
pastebin.com / raw/0CGTpiEn
psirt.bosch.com / security-advisories/BOSCH-SA-341298-BT.html