Vulnerability Description
BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device password.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bosch | Bf-Os | >= 3.0, <= 3.83 |
Related Weaknesses (CWE)
References
- https://psirt.bosch.com/security-advisories/bosch-sa-013924-bt.htmlVendor Advisory
- https://psirt.bosch.com/security-advisories/bosch-sa-013924-bt.htmlVendor Advisory
FAQ
What is CVE-2022-36301?
CVE-2022-36301 is a vulnerability with a CVSS score of 9.8 (CRITICAL). BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device password.
How severe is CVE-2022-36301?
CVE-2022-36301 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-36301?
Check the references section above for vendor advisories and patch information. Affected products include: Bosch Bf-Os.