Vulnerability Details CVE-2022-32536
The user access rights validation in the web server of the Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 was insufficient. This would allow a non-administrator user to obtain administrator user access rights.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.4%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 9.0
Products affected by CVE-2022-32536
-
cpe:2.3:h:bosch:pra-es8p2s:-
-
cpe:2.3:o:bosch:pra-es8p2s_firmware:-
-
cpe:2.3:o:bosch:pra-es8p2s_firmware:1.01.05