CVE-2025-60038
7.8Bosch Rexroth · IndraWorks
Bosch Rexroth IndraWorks is vulnerable to remote code execution via insecure deserialization of untrusted data, requiring user interaction to open a malicious file.
Executive summary
A critical remote code execution vulnerability exists in Bosch Rexroth IndraWorks that allows attackers to compromise systems through the processing of maliciously crafted files.
Vulnerability
The software suffers from CWE-502, which is the deserialization of untrusted data. An attacker can achieve remote code execution by providing a specially crafted file that the application deserializes, requiring user interaction to trigger the flaw.
Business impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary code with the privileges of the user running the application. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to a total system compromise, unauthorized data access, and potential lateral movement within the operational network.
Remediation
Immediate Action: Review the official Bosch PSIRT advisory for available patches or configuration workarounds, as no specific patch version is currently identified. If a patch is not yet available, restrict the opening of untrusted or externally sourced files within the IndraWorks environment.
Proactive Monitoring: Monitor system logs for unexpected child processes or abnormal behavior originating from the IndraWorks application process.
Compensating Controls: Deploy endpoint detection and response (EDR) solutions to identify and block suspicious file execution patterns associated with deserialization attacks.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations utilizing Bosch Rexroth IndraWorks must prioritize the review of the vendor's security advisory to identify remediation steps. Because this vulnerability facilitates remote code execution, it is imperative to implement strict file handling policies and monitor for any suspicious activity until a permanent patch is applied.
More Bosch Rexroth CVEs
Sources
- https://psirt.bosch.com/security-advisories/BOSCH-SA-591522.html Vendor advisory