Executive brief
Bosch Configuration Manager, a tool used to manage and configure security systems and devices, contains a vulnerability that allows sensitive information to be accessed by unauthorized users. An attacker with local access to the system could retrieve protected data, potentially leading to unauthorized configuration changes or broader access to the managed security infrastructure. This could compromise the integrity of the security environment and expose administrative credentials or system secrets.
Technical details
An information disclosure vulnerability exists in Bosch Configuration Manager version 7.72.0106 due to the cleartext storage of sensitive information (CWE-312). The flaw allows a local attacker with low privileges to access sensitive data that should be protected. According to the CVSS vector, the vulnerability has a high impact on confidentiality and integrity and involves a scope jump, suggesting that the compromised information could be used to affect other components of the system. Exploitation requires local access but no user interaction. Users should contact the vendor for patching information or upgrade to a non-affected version if available.
Affected products
- Bosch Configuration Manager 7.72.0106
Timeline
- 2026-07-23: advisory: NVD publication date