CVE-2025-41690

7.4

Endress+Hauser · Promag 10 and Promass 10

A vulnerability in Endress+Hauser Promag 10 and Promass 10 devices allows low-privileged attackers within Bluetooth range to extract maintenance passwords from event logs.

Executive summary

A high-severity information disclosure vulnerability in Endress+Hauser flowmeters allows local attackers to escalate privileges by accessing sensitive credentials stored in device event logs.

Vulnerability

This flaw, categorized as CWE-532, involves the improper inclusion of sensitive information into log files. A low-privileged attacker within Bluetooth range can view the device event log to obtain maintenance passwords, enabling unauthorized authentication as a Maintenance user.

Business impact

Successful exploitation grants an attacker full administrative control over critical industrial instrumentation. This compromise allows for the unauthorized modification of device parameters and configuration settings, which could lead to process disruption, physical equipment damage, or significant operational safety risks. The CVSS score of 7.4 reflects the high impact on confidentiality, integrity, and availability.

Remediation

Immediate Action: Update affected Promag 10 and Promass 10 devices to the patched firmware versions listed in the vendor advisory (VDE-2025-068).

Proactive Monitoring: Audit device access logs for unauthorized Bluetooth connection attempts or suspicious interaction with the event logging system.

Compensating Controls: Restrict physical access to the affected devices to prevent unauthorized parties from entering the necessary Bluetooth range, and disable Bluetooth interfaces if they are not required for current operations.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of these devices in industrial environments, immediate firmware updates are required to eliminate the credential exposure risk. Organizations should prioritize patching, especially for devices deployed in sensitive or physically accessible locations, and ensure that Bluetooth interface security policies are strictly enforced.

Sources