CVE-2026-56428
Bosch · BSH ELP (Electronic Platform) Modules
The SSH service on Bosch BSH ELP modules is vulnerable to incorrect user management due to an insecure default configuration.
Executive summary
An insecure default configuration in the SSH service of Bosch BSH ELP modules exposes systems to unauthorized access and potential full system compromise.
Vulnerability
This vulnerability involves incorrect user management (CWE-286) within the SSH service. The issue is remotely exploitable and does not require authentication, though it requires high attack complexity.
Business impact
The vulnerability carries a CVSS score of 8.1, indicating a high severity risk. Successful exploitation could allow an attacker to gain unauthorized access to the underlying platform, potentially leading to total system control, data exfiltration, or the disruption of critical operations managed by the BSH ELP modules.
Remediation
Immediate Action: Update Bosch BSH ELP modules to firmware version 65.2.12 or later to address the insecure default configuration.
Proactive Monitoring: Monitor network traffic for unusual SSH connection attempts and review authentication logs for unauthorized access patterns.
Compensating Controls: Restrict SSH access to the affected modules to trusted management subnets using network firewalls to reduce the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the critical nature of the modules and the potential for total system compromise, administrators should prioritize patching these devices. Apply the provided firmware update immediately to eliminate the insecure default configuration and prevent unauthorized administrative access.