CVE-2026-56428

Bosch · BSH ELP (Electronic Platform) Modules

The SSH service on Bosch BSH ELP modules is vulnerable to incorrect user management due to an insecure default configuration.

Executive summary

An insecure default configuration in the SSH service of Bosch BSH ELP modules exposes systems to unauthorized access and potential full system compromise.

Vulnerability

This vulnerability involves incorrect user management (CWE-286) within the SSH service. The issue is remotely exploitable and does not require authentication, though it requires high attack complexity.

Business impact

The vulnerability carries a CVSS score of 8.1, indicating a high severity risk. Successful exploitation could allow an attacker to gain unauthorized access to the underlying platform, potentially leading to total system control, data exfiltration, or the disruption of critical operations managed by the BSH ELP modules.

Remediation

Immediate Action: Update Bosch BSH ELP modules to firmware version 65.2.12 or later to address the insecure default configuration.

Proactive Monitoring: Monitor network traffic for unusual SSH connection attempts and review authentication logs for unauthorized access patterns.

Compensating Controls: Restrict SSH access to the affected modules to trusted management subnets using network firewalls to reduce the attack surface.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical nature of the modules and the potential for total system compromise, administrators should prioritize patching these devices. Apply the provided firmware update immediately to eliminate the insecure default configuration and prevent unauthorized administrative access.