CVE-2025-60036

7.8

Bosch Rexroth · IndraWorks, UA.Testclient

A deserialization vulnerability in Bosch Rexroth IndraWorks and UA.Testclient allows local attackers to achieve remote code execution by tricking users into opening a malicious file.

Executive summary

A critical remote code execution vulnerability exists in Bosch Rexroth IndraWorks and UA.Testclient, which can be triggered by processing a specially crafted file.

Vulnerability

The software is vulnerable to CWE-502, which involves the insecure deserialization of untrusted data. An attacker can leverage this flaw by providing a manipulated file that, when opened by an unsuspecting user, leads to arbitrary code execution on the host system.

Business impact

The ability to execute arbitrary code on a user system poses a severe risk to organizational security, potentially resulting in complete system compromise, data theft, and loss of integrity. Given the CVSS score of 7.8, this high-severity vulnerability necessitates prompt attention to prevent unauthorized control over workstations running the affected engineering software.

Remediation

Immediate Action: Update Bosch Rexroth IndraWorks to version 15V24 or later and UA.Testclient to version 2.9.0 or later to include the necessary security patches.

Proactive Monitoring: Monitor workstation activity for unexpected child processes spawned by the UA.Testclient utility or abnormal file access patterns.

Compensating Controls: Implement strict file access policies and user awareness training to discourage the opening of untrusted or suspicious files within the engineering environment.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing Bosch Rexroth engineering software must prioritize the application of the provided vendor updates. Given the potential for total system compromise, administrators should verify that all affected installations of IndraWorks and UA.Testclient are patched to the specified versions to mitigate the risks associated with deserialization attacks.

More Bosch Rexroth CVEs

Sources