CVE-2022-32534
CRITICALCVSS 9.8/10EPSS 2.29%
Last modified
CVE-2022-32534 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command injection through its diagnostics web interface. This allows execution of shell commands.. EPSS estimates a 2.29% chance of exploitation in the next 30 days.
Description
The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command injection through its diagnostics web interface. This allows execution of shell commands.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bosch | Pra-Es8p2s Firmware | <= 1.01.05 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-32534?
The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command injection through its diagnostics web interface. This allows execution of shell commands.
How severe is CVE-2022-32534?
CVE-2022-32534 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 2.29% probability of exploitation in the next 30 days.
How do I fix CVE-2022-32534?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-32528 A CWE-306: Missing Authentication for Critical Function vul…9.1
- CVE-2022-32529A CWE-120: Buffer Copy without Checking Size of Input vulner…9.8
- CVE-2022-32530A CWE-668 Exposure of Resource to Wrong Sphere vulnerability…7.8
- CVE-2022-32531The Apache Bookkeeper Java Client (before 4.14.6 and also 4.…5.9
- CVE-2022-32532Apache Shiro before 1.9.1, A RegexRequestMatcher can be misc…9.8
- CVE-2022-32533Apache Jetspeed-2 does not sufficiently filter untrusted use…9.8
- CVE-2022-32535The Bosch Ethernet switch PRA-ES8P2S with software version 1…9.8
- CVE-2022-32536The user access rights validation in the web server of the B…8.8
- CVE-2022-32537A vulnerability exists which could allow an unauthorized use…4.8
- CVE-2022-3254The WordPress Classifieds Plugin WordPress plugin before 4.3…9.8
- CVE-2022-32540Information Disclosure in Operator Client application in BVM…5.9
- CVE-2022-32543An integer overflow vulnerability exists in the way ESTsoft …7.8
Are you affected by CVE-2022-32534?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
