CVE-2025-41690
7.4Endress+Hauser · Promag 10 and Promass 10
A vulnerability in Endress+Hauser Promag 10 and Promass 10 devices allows low-privileged attackers within Bluetooth range to extract maintenance passwords from event logs.
Executive summary
A high-severity information disclosure vulnerability in Endress+Hauser flowmeters allows local attackers to escalate privileges by accessing sensitive credentials stored in device event logs.
Vulnerability
This flaw, categorized as CWE-532, involves the improper inclusion of sensitive information into log files. A low-privileged attacker within Bluetooth range can view the device event log to obtain maintenance passwords, enabling unauthorized authentication as a Maintenance user.
Business impact
Successful exploitation grants an attacker full administrative control over critical industrial instrumentation. This compromise allows for the unauthorized modification of device parameters and configuration settings, which could lead to process disruption, physical equipment damage, or significant operational safety risks. The CVSS score of 7.4 reflects the high impact on confidentiality, integrity, and availability.
Remediation
Immediate Action: Update affected Promag 10 and Promass 10 devices to the patched firmware versions listed in the vendor advisory (VDE-2025-068).
Proactive Monitoring: Audit device access logs for unauthorized Bluetooth connection attempts or suspicious interaction with the event logging system.
Compensating Controls: Restrict physical access to the affected devices to prevent unauthorized parties from entering the necessary Bluetooth range, and disable Bluetooth interfaces if they are not required for current operations.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical nature of these devices in industrial environments, immediate firmware updates are required to eliminate the credential exposure risk. Organizations should prioritize patching, especially for devices deployed in sensitive or physically accessible locations, and ensure that Bluetooth interface security policies are strictly enforced.