« Volver al listado

CVE-2022-36302

Estado: ModificadaMedia (5.4)—

File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access different resources, which may contain sensitive information.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-36302",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@bosch.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@bosch.com",
      "affectedData": [
        {
          "vendor": "Bosch",
          "product": "BF-OS",
          "versions": [
            {
              "status": "affected",
              "version": "3.0",
              "versionType": "custom",
              "lessThanOrEqual": "3.83"
            }
          ],
          "platforms": [
            "Bigfish V3 (Linux)"
          ]
        },
        {
          "vendor": "Bosch",
          "product": "BF-OS",
          "versions": [
            {
              "status": "affected",
              "version": "3.0",
              "versionType": "custom",
              "lessThanOrEqual": "3.83"
            }
          ],
          "platforms": [
            "PR21 (Linux)"
          ]
        },
        {
          "vendor": "Bosch",
          "product": "BF-OS",
          "versions": [
            {
              "status": "affected",
              "version": "3.0",
              "versionType": "custom",
              "lessThanOrEqual": "3.83"
            }
          ],
          "platforms": [
            "VM (Windows)"
          ]
        }
      ]
    }
  ],
  "published": "2022-08-01T14:15:10.117",
  "references": [
    {
      "url": "https://psirt.bosch.com/security-advisories/bosch-sa-013924-bt.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@bosch.com"
    },
    {
      "url": "https://psirt.bosch.com/security-advisories/bosch-sa-013924-bt.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@bosch.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-641"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-74"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access different resources, which may contain sensitive information."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de manipulación de rutas de archivos en BF-OS versiones 3.00 hasta 3.83 incluyéndola, que permite a un atacante modificar la ruta de archivos para acceder a diferentes recursos, que pueden contener información confidencial"
    }
  ],
  "lastModified": "2026-06-17T04:53:11.460",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:bosch:bf-os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D23B1230-BB4F-445C-B962-D06BDE25979B",
              "versionEndIncluding": "3.83",
              "versionStartIncluding": "3.00"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@bosch.com"
}