Description
Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.
Published: 2026-07-23
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Bosch Configuration Manager version 7.72.0106 allows an attacker to read sensitive data that should be protected, creating a confidentiality breach. The weakness falls under the realm of improper information access, which could expose configuration secrets or other confidential material. While the description does not detail the exact exploitation method, the impact is a loss of confidentiality that could affect system integrity if sensitive data is exposed to malicious actors.

Affected Systems

Bosch Configuration Manager, version 7.72.0106 is the only product explicitly enumerated as vulnerable. Administrators should verify that the deployed instance matches this version string and review any other releases that may share the same code base for similar exposure.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity with a significant confidentiality impact. However, the EPSS score is listed as < 1%, suggesting that, while serious, the probability of exploitation is currently very low. The vulnerability is not listed in the CISA KEV catalog. The lack of explicit attack vector details in the advisory means the method of exploitation is not disclosed; it could involve local or remote access with authorized credentials, but this remains inferred rather than confirmed.

Generated by OpenCVE AI on August 4, 2026 at 15:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Bosch Configuration Manager update that resolves the information disclosure bug.
  • Review and tighten access controls to configuration files so that only authorized administrators can read them.
  • If immediate updating is not possible, isolate the configuration manager by limiting its network exposure through firewalls or segmentation to prevent unauthorized access.

Generated by OpenCVE AI on August 4, 2026 at 15:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Information Disclosure Vulnerability in Bosch Configuration Manager 7.72.0106

Sun, 02 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Information Disclosure Vulnerability in Bosch Configuration Manager 7.72.0106

Sat, 01 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Information Disclosure in Bosch Configuration Manager Version 7.72.0106

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Bosch
Bosch configuration Manager
Vendors & Products Bosch
Bosch configuration Manager

Sun, 26 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Information Disclosure in Bosch Configuration Manager Version 7.72.0106

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Bosch Configuration Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: bosch

Published:

Updated: 2026-07-23T13:59:46.842Z

Reserved: 2026-07-23T07:45:15.711Z

Link: CVE-2024-58023

cve-icon Vulnrichment

Updated: 2026-07-23T13:59:43.826Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-23T09:16:26.290

Modified: 2026-07-23T15:48:25.133

Link: CVE-2024-58023

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:45:03Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information