CVE-2026-56428: CWE-286 Incorrect User Management in Bosch BSH ELP (Electronic Platform) Modules
The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. An insecure, non-revocable SSH public key is included in the firmware's authorized_keys file for the root user. An attacker in possession of the corresponding private key could leverage it to bypass authentication and gain root-level access to the appliance.
AI Analysis
Technical Summary
The vulnerability arises from an improperly secured default configuration in the SSH service of Bosch BSH ELP modules. Specifically, the firmware includes a non-revocable SSH public key in the root user's authorized_keys file. An attacker possessing the matching private key can authenticate as root without further credentials, leading to full control over the device. This is classified under CWE-286 (Incorrect User Management). The CVSS v3.1 base score is 8.1, reflecting network attack vector, high impact on confidentiality, integrity, and availability, and requiring no user interaction but high attack complexity.
Potential Impact
Successful exploitation grants an attacker root-level access to the affected appliance, compromising confidentiality, integrity, and availability of the system. This could allow complete control over the device and potentially the environment it operates within.
Mitigation Recommendations
No official patch or remediation is currently available from Bosch. Users should monitor Bosch advisories for updates. Until a fix is released, restricting network access to the affected devices and employing compensating controls to limit exposure of the SSH service is recommended. Avoid using version 65.0.0 where possible.
CVE-2026-56428: CWE-286 Incorrect User Management in Bosch BSH ELP (Electronic Platform) Modules
Description
The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. An insecure, non-revocable SSH public key is included in the firmware's authorized_keys file for the root user. An attacker in possession of the corresponding private key could leverage it to bypass authentication and gain root-level access to the appliance.
CVSS v3.1
Score 8.1high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises from an improperly secured default configuration in the SSH service of Bosch BSH ELP modules. Specifically, the firmware includes a non-revocable SSH public key in the root user's authorized_keys file. An attacker possessing the matching private key can authenticate as root without further credentials, leading to full control over the device. This is classified under CWE-286 (Incorrect User Management). The CVSS v3.1 base score is 8.1, reflecting network attack vector, high impact on confidentiality, integrity, and availability, and requiring no user interaction but high attack complexity.
Potential Impact
Successful exploitation grants an attacker root-level access to the affected appliance, compromising confidentiality, integrity, and availability of the system. This could allow complete control over the device and potentially the environment it operates within.
Mitigation Recommendations
No official patch or remediation is currently available from Bosch. Users should monitor Bosch advisories for updates. Until a fix is released, restricting network access to the affected devices and employing compensating controls to limit exposure of the SSH service is recommended. Avoid using version 65.0.0 where possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- bosch
- Date Reserved
- 2026-06-26T10:55:30.996Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6b50219c2644c7f81fdcba
Added to database: 07/30/2026, 13:22:41 UTC
Last enriched: 07/30/2026, 13:37:09 UTC
Last updated: 07/30/2026, 22:52:26 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.