U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2022-47648

Change History

CVE Modified by MITRE 5/04/2023 5:15:09 PM

Action Type Old Value New Value
Added CVSS V3.1

								
							
							
						
MITRE AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Changed Description
** UNSUPPORTED WHEN ASSIGNED ** Bosch Security Systems B420 firmware 02.02.0001 employs IP based authorization in its authentication mechanism, allowing attackers to access the device as long as they are on the same network as a legitimate user.
An Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring any sort of authorization or authentication due to the IP based authorization. If an authorized user has accessed a publicly available B420 product using valid credentials, an insider attacker can gain access to the same panel without requiring any sort of authorization. The B420 module was already obsolete at the time this vulnerability was found (The End of Life announcement was made in 2013).
Added Reference

								
							
							
						
https://psirt.bosch.com/security-advisories/BOSCH-SA-341298-BT.html [No Types Assigned]