Логотип exploitDog
bind:CVE-2022-47648
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-47648

Количество 3

Количество 3

nvd логотип

CVE-2022-47648

около 3 лет назад

An Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring any sort of authorization or authentication due to the IP based authorization. If an authorized user has accessed a publicly available B420 product using valid credentials, an insider attacker can gain access to the same panel without requiring any sort of authorization. The B420 module was already obsolete at the time this vulnerability was found (The End of Life announcement was made in 2013).

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-c56p-rh7r-f3v9

около 3 лет назад

Bosch Security Systems B420 firmware 02.02.0001 employs IP based authorization in its authentication mechanism, allowing attackers to access the device as long as they are on the same network as a legitimate user.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2023-00801

около 3 лет назад

Уязвимость панели управления микропрограммного обеспечения коммуникационных Ethernet-модулей Bosch B420, позволяющая нарушителю обойти ограничения безопасности и получить несанкционированный доступ к защищаемой информации

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-47648

An Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring any sort of authorization or authentication due to the IP based authorization. If an authorized user has accessed a publicly available B420 product using valid credentials, an insider attacker can gain access to the same panel without requiring any sort of authorization. The B420 module was already obsolete at the time this vulnerability was found (The End of Life announcement was made in 2013).

CVSS3: 7.6
0%
Низкий
около 3 лет назад
github логотип
GHSA-c56p-rh7r-f3v9

Bosch Security Systems B420 firmware 02.02.0001 employs IP based authorization in its authentication mechanism, allowing attackers to access the device as long as they are on the same network as a legitimate user.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2023-00801

Уязвимость панели управления микропрограммного обеспечения коммуникационных Ethernet-модулей Bosch B420, позволяющая нарушителю обойти ограничения безопасности и получить несанкционированный доступ к защищаемой информации

CVSS3: 7.8
0%
Низкий
около 3 лет назад

Уязвимостей на страницу