The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. An insecure, non-revocable SSH public key is included in the firmware's authorized_keys file for the root user. An attacker in possession of the corresponding private key could leverage it to bypass authentication and gain root-level access to the appliance.
Metrics
Affected Vendors & Products
References
History
Thu, 30 Jul 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bosch
Bosch bsh Elp (electronic Platform) Modules |
|
| Vendors & Products |
Bosch
Bosch bsh Elp (electronic Platform) Modules |
Thu, 30 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. An insecure, non-revocable SSH public key is included in the firmware's authorized_keys file for the root user. An attacker in possession of the corresponding private key could leverage it to bypass authentication and gain root-level access to the appliance. | |
| Weaknesses | CWE-286 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: bosch
Published:
Updated: 2026-07-30T15:10:44.082Z
Reserved: 2026-06-26T10:55:30.996Z
Link: CVE-2026-56428
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T15:28:54Z