CVE-2025-60037
7.8Bosch Rexroth · IndraWorks
Bosch Rexroth IndraWorks is vulnerable to remote code execution via insecure deserialization of untrusted data when a user opens a specially crafted file.
Executive summary
A critical deserialization vulnerability in Bosch Rexroth IndraWorks allows an attacker to achieve remote code execution on the host system through a manipulated file.
Vulnerability
This vulnerability stems from improper deserialization of untrusted data (CWE-502). An attacker can trigger remote code execution by tricking a user into opening a specially crafted file within the application.
Business impact
Successful exploitation leads to a complete compromise of the system running the affected software. Given the CVSS score of 7.8, this vulnerability poses a significant risk to operational integrity, potentially allowing unauthorized access to sensitive industrial control data and facilitating lateral movement within the network.
Remediation
Immediate Action: Review the official Bosch PSIRT security advisory at https://psirt.bosch.com/security-advisories/BOSCH-SA-591522.html to determine if a patch is available for your specific deployment.
Proactive Monitoring: Monitor system logs for unusual application behavior or unexpected file access patterns that may indicate an attempt to trigger malicious deserialization.
Compensating Controls: Implement strict file validation policies and restrict user permissions to prevent the execution of untrusted or externally sourced files within the IndraWorks environment.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this flaw necessitates immediate attention from administrators responsible for Bosch Rexroth environments. Until a formal patch is applied, ensure that users are advised against opening untrusted files with IndraWorks and maintain vigilant monitoring of system integrity to mitigate the risk of remote code execution.
More Bosch Rexroth CVEs
Sources
- https://psirt.bosch.com/security-advisories/BOSCH-SA-591522.html Vendor advisory