Bosch ctrlX OS Network Interfaces Vulnerability Allowing Deletion of Network Configuration
Vulnerability
A vulnerability exists in the Network Interfaces functionality of the ctrlX OS web application. It allows a remote authenticated (low-privileged) attacker to delete the configuration of physical network interfaces by sending a crafted HTTP request. This issue affects Bosch Rexroth AG ctrlX OS versions 1.12.0 through 1.12.9, 1.20.0 through 1.20.7, and 2.6.0 through 2.6.8.
Impact
Exploitation of this vulnerability leads to the unauthorized deletion of network interface configurations, potentially causing disruption in network connectivity or functionality.
Remediation
Users are advised to update to the latest versions of the affected ctrlX OS applications. The update may require a device reboot. To check if the updated versions are installed, use the device's package management system.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
