CVE-2025-12508

8.4

Bizerba · BRAIN2

Bizerba BRAIN2 transmits communication with Active Directory services in cleartext when using domain users, leading to potential interception of authentication data.

Executive summary

A high-severity vulnerability in Bizerba BRAIN2 allows for the interception of sensitive authentication data due to unencrypted communication with Active Directory services.

Vulnerability

The software uses cleartext transmission for Active Directory communications (CWE-319), which can be exploited by an attacker with high privileges to intercept sensitive authentication credentials.

Business impact

The vulnerability carries a CVSS score of 8.4, indicating a high risk of credential theft and subsequent unauthorized access to the environment. Successful exploitation compromises the confidentiality of domain user sessions, potentially leading to full system compromise or lateral movement within the network.

Remediation

Immediate Action: Update Bizerba BRAIN2 to version 3.07 or later to implement encrypted communication channels.

Proactive Monitoring: Review Active Directory and application access logs for any anomalous connection patterns or unauthorized credential validation attempts.

Compensating Controls: Ensure that the communication between BRAIN2 and Active Directory is restricted to secure, isolated network segments and implement network-level encryption where possible until the patch is applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for complete compromise of domain credentials, this vulnerability poses a significant risk to organizational identity security. Administrators must prioritize the transition to version 3.07 immediately to remediate the cleartext transmission flaw and protect Active Directory interactions from interception.

Sources