Impact
The flaw in Bosch Configuration Manager version 7.72.0106 allows an attacker to read sensitive data that should be protected, creating a confidentiality breach. The weakness falls under the realm of improper information access, which could expose configuration secrets or other confidential material. While the description does not detail the exact exploitation method, the impact is a loss of confidentiality that could affect system integrity if sensitive data is exposed to malicious actors.
Affected Systems
Bosch Configuration Manager, version 7.72.0106 is the only product explicitly enumerated as vulnerable. Administrators should verify that the deployed instance matches this version string and review any other releases that may share the same code base for similar exposure.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity with a significant confidentiality impact. However, the EPSS score is listed as < 1%, suggesting that, while serious, the probability of exploitation is currently very low. The vulnerability is not listed in the CISA KEV catalog. The lack of explicit attack vector details in the advisory means the method of exploitation is not disclosed; it could involve local or remote access with authorized credentials, but this remains inferred rather than confirmed.
OpenCVE Enrichment