CVE-2025-12508
8.4Bizerba · BRAIN2
Bizerba BRAIN2 transmits communication with Active Directory services in cleartext when using domain users, leading to potential interception of authentication data.
Executive summary
A high-severity vulnerability in Bizerba BRAIN2 allows for the interception of sensitive authentication data due to unencrypted communication with Active Directory services.
Vulnerability
The software uses cleartext transmission for Active Directory communications (CWE-319), which can be exploited by an attacker with high privileges to intercept sensitive authentication credentials.
Business impact
The vulnerability carries a CVSS score of 8.4, indicating a high risk of credential theft and subsequent unauthorized access to the environment. Successful exploitation compromises the confidentiality of domain user sessions, potentially leading to full system compromise or lateral movement within the network.
Remediation
Immediate Action: Update Bizerba BRAIN2 to version 3.07 or later to implement encrypted communication channels.
Proactive Monitoring: Review Active Directory and application access logs for any anomalous connection patterns or unauthorized credential validation attempts.
Compensating Controls: Ensure that the communication between BRAIN2 and Active Directory is restricted to secure, isolated network segments and implement network-level encryption where possible until the patch is applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for complete compromise of domain credentials, this vulnerability poses a significant risk to organizational identity security. Administrators must prioritize the transition to version 3.07 immediately to remediate the cleartext transmission flaw and protect Active Directory interactions from interception.