PT-2024-20692 · Bosch · Bosch Network Synchronizer

CVE-2024-25002

·

Published

2024-03-25

·

Updated

2024-03-26

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bosch Network Synchronizer (affected versions not specified)
Description Command Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access to the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-25002

Affected Products

Bosch Network Synchronizer