CVE-2024-58023

Bosch · Configuration Manager

A vulnerability in Bosch Configuration Manager version 7 allows for the cleartext storage of sensitive information, potentially leading to unauthorized data exposure.

Executive summary

Bosch Configuration Manager version 7.72.0106 contains a cleartext storage vulnerability that poses a high risk to sensitive configuration data.

Vulnerability

The software suffers from the cleartext storage of sensitive information (CWE-312). An authenticated attacker with local access can exploit this to retrieve sensitive data, such as credentials, which may be stored insecurely.

Business impact

With a CVSS score of 8.4, this vulnerability presents a significant risk to the security of managed infrastructure. If an attacker gains access to sensitive information stored in cleartext, they could facilitate lateral movement or further unauthorized access to integrated systems, resulting in a breach of operational security.

Remediation

Immediate Action: Refer to the vendor security advisory (BOSCH-SA-981803) and apply the recommended updates or configuration changes provided by Bosch.

Proactive Monitoring: Audit configuration files and local storage directories for sensitive data stored in plaintext.

Compensating Controls: Restrict local access to the machine running the Configuration Manager to only essential personnel.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Security teams should treat this cleartext storage issue with high urgency. Perform the necessary updates and ensure that sensitive configurations are protected according to the vendor's updated security guidelines.