Browse all 70 CVE security advisories affecting Bosch. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Bosch operates as a global supplier of technology and services, primarily focusing on automotive components, industrial technology, consumer goods, and security systems. With seventy recorded Common Vulnerabilities and Exposures, the company’s attack surface is largely defined by its extensive Internet of Things (IoT) portfolio and embedded software infrastructure. Historically, disclosed flaws frequently involve remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from insecure default configurations or insufficient input validation within connected devices. These weaknesses pose significant risks to operational integrity, particularly in industrial control systems and smart home ecosystems. While no single catastrophic breach has dominated public discourse, the sheer volume of vulnerabilities highlights systemic challenges in securing diverse, legacy-integrated hardware. Security assessments emphasize the need for rigorous lifecycle management and continuous patching across its vast, interconnected product lines to mitigate potential exploitation vectors.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2021-23851 | Buffer Overflow vulnerability in the recovery image web-based interface — CPP FirmwareCWE-121 | 6.8 | Medium | 2022-03-30 |
| CVE-2021-23850 | Buffer Overflow vulnerability in the recovery image telnet server — CPP FirmwareCWE-121 | 6.8 | Medium | 2022-03-30 |
| CVE-2021-23849 | Cross Site Request Forgery (CSRF) vulnerability in web based management interface — CPP FirmwareCWE-352 | 7.5 | High | 2021-08-05 |
| CVE-2021-23854 | Reflected XSS in page parameter — CPP FirmwareCWE-79 | 8.3 | High | 2021-06-09 |
| CVE-2021-23847 | Unauthenticated Information Extraction Vulnerability — CPP FirmwareCWE-287 | 9.8 | Critical | 2021-06-09 |
| CVE-2021-23853 | Improper Input Validation of HTTP Headers — CPP FirmwareCWE-20 | 8.3 | High | 2021-06-09 |
| CVE-2021-23848 | Reflected XSS in URL handler — CPP FirmwareCWE-79 | 8.3 | High | 2021-06-09 |
| CVE-2021-23852 | Denial of Service (DoS) due to invalid web parameter — CPP FirmwareCWE-400 | 4.9 | Medium | 2021-06-09 |
This page lists every published CVE security advisory associated with Bosch. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.