The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. An insecure, non-revocable SSH public key is included in the firmware's authorized_keys file for the root user. An attacker in possession of the corresponding private key could leverage it to bypass authentication and gain root-level access to the appliance.
Metrics
Affected Vendors & Products
References
History
Fri, 31 Jul 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insecure SSH Public Key Allows Root Access on Bosch BSH ELP Modules |
Thu, 30 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Jul 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bosch
Bosch bsh Elp (electronic Platform) Modules |
|
| Vendors & Products |
Bosch
Bosch bsh Elp (electronic Platform) Modules |
Thu, 30 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. An insecure, non-revocable SSH public key is included in the firmware's authorized_keys file for the root user. An attacker in possession of the corresponding private key could leverage it to bypass authentication and gain root-level access to the appliance. | |
| Weaknesses | CWE-286 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: bosch
Published: 2026-07-30T13:11:11.395Z
Updated: 2026-07-30T15:10:44.082Z
Reserved: 2026-06-26T10:55:30.996Z
Link: CVE-2026-56428
Updated: 2026-07-30T15:10:36.648Z
No data.
No data.