Bizerba GLx and CWx Device Firmware Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in Bizerba device firmware for the GLx and CWx product families, versions prior to 16.20. An authenticated attacker can exploit this vulnerability over the network by using public FTP access to upload large amounts of data to the device's mass storage. This unregulated data transfer can completely fill the storage capacity, thereby compromising the device's availability.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, where the device becomes unavailable due to excessive storage being consumed by uploaded data.

Remediation

Users are advised to update to the latest version of the device firmware. Additionally, access to FTP and SFTP should be restricted for unauthorized individuals or these services should be disabled.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.