CVE-2023-49722 describes a vulnerability in Bosch BCC101, BCC102, and BCC50 smart thermostat firmware, where network port 8899 is unintentionally left open. This allows an attacker on the same Wi-Fi network to connect to the device. Rated as Medium severity (CVSS 6.5), the vulnerability has a low attack complexity and requires network adjacency, with a potential impact of high integrity compromise but no confidentiality or availability impact. There is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.13.20, < 4.13.33CPE matchmatch criteria | cpe:2.3:o:bosch:bcc101_firmware:*:*:*:*:*:*:*:* | ||
>= 4.13.20, < 4.13.33CPE matchmatch criteria | cpe:2.3:o:bosch:bcc102_firmware:*:*:*:*:*:*:*:* | ||
>= 4.13.20, < 4.13.33CPE matchmatch criteria | cpe:2.3:o:bosch:bcc50_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Open Port 8899 in BCC Thermostat Product
Jan 9, 2024Open Port 8899 in BCC Thermostat Product
Jan 9, 2024Open Port 8899 in BCC Thermostat Product
Jan 9, 2024Open Port 8899 in BCC Thermostat Product
Jan 9, 2024