Description
A vulnerability in the web application of the ctrlX OS setup mechanism facilitated an authenticated (low privileged) attacker to gain remote access to backup archives created by a user with elevated permissions. Depending on the content of the backup archive, the attacker may have been able to access sensitive data.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Bosch Rexroth AG / ctrlX OS - Setup1.20.0 – 1.20.1
- Bosch Rexroth AG / ctrlX OS - Setup2.6.0 – 2.6.1
- Bosch Rexroth AG / ctrlX OS - Setup3.6.0 – 3.6.2