CVE-2024-58023
Bosch · Configuration Manager
A vulnerability in Bosch Configuration Manager version 7 allows for the cleartext storage of sensitive information, potentially leading to unauthorized data exposure.
Executive summary
Bosch Configuration Manager version 7.72.0106 contains a cleartext storage vulnerability that poses a high risk to sensitive configuration data.
Vulnerability
The software suffers from the cleartext storage of sensitive information (CWE-312). An authenticated attacker with local access can exploit this to retrieve sensitive data, such as credentials, which may be stored insecurely.
Business impact
With a CVSS score of 8.4, this vulnerability presents a significant risk to the security of managed infrastructure. If an attacker gains access to sensitive information stored in cleartext, they could facilitate lateral movement or further unauthorized access to integrated systems, resulting in a breach of operational security.
Remediation
Immediate Action: Refer to the vendor security advisory (BOSCH-SA-981803) and apply the recommended updates or configuration changes provided by Bosch.
Proactive Monitoring: Audit configuration files and local storage directories for sensitive data stored in plaintext.
Compensating Controls: Restrict local access to the machine running the Configuration Manager to only essential personnel.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Security teams should treat this cleartext storage issue with high urgency. Perform the necessary updates and ensure that sensitive configurations are protected according to the vendor's updated security guidelines.