Sceawere
Vulnerability Detail
CVE-2024-58023Updated Verified Sceawere Triage Sources: NVD / CISA KEV
Bosch Configuration Manager Information Disclosure
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.4
- Creation Date
- 2h ago
- Vendor
- Bosch
- Product
- Bosch Configuration Manager
- Attack Type
- CWE-312 Cleartext Storage of Sensitive Information
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.4",
"pubDate": "2026-07-23T09:16:26.290Z",
"pubdate": "2026-07-23T09:16:26.290Z",
"executiveSummary": "An information disclosure vulnerability has been identified in Bosch Configuration Manager version 7.72.0106. This security flaw allows an unauthorized or privileged attacker to access sensitive information stored, processed, or transmitted by the application.\nThe primary impact of this vulnerability involves the unauthorized exposure of confidential data, which may include system configurations, credentials, or operational parameters managed by the affected software.\nThe affected product is Bosch Configuration Manager, specifically version 7.72.0106. The risk implication is moderate to high depending on the sensitivity of the exposed data and the exposure level of the target system within the network architecture.\nExploitation of this vulnerability requires network access to the vulnerable component and typically involves interacting with application interfaces or endpoints that fail to properly enforce access controls or data sanitization.\nSuccessful exploitation grants the adversary visibility into internal operational data, potentially facilitating subsequent attack vectors such as unauthorized system access, privilege escalation, or further reconnaissance against connected security and surveillance infrastructure.",
"technicalDetails": "The vulnerability resides within Bosch Configuration Manager version 7.72.0106, specifically within components responsible for handling data retrieval or client-server communications.\nThe root cause stems from insufficient access control enforcement, improper authorization checks, or insecure data handling practices, which permit direct or indirect access to sensitive internal resources without adequate validation of the requester's privileges.\nFrom a network exposure perspective, the vulnerable component listens for incoming requests or facilitates internal data exchanges, allowing potential adversaries who have network connectivity to interact with the affected endpoints.\nThe attack flow typically proceeds with the attacker identifying the target endpoint or interface associated with Bosch Configuration Manager version 7.72.0106. The attacker then constructs a targeted request, such as a specific API call, web request, or protocol-level interaction designed to query the vulnerable component.\nBecause the application lacks proper authorization mechanisms or data filtering logic at the vulnerable interface, it processes the request and returns the sensitive information directly to the requester in the response payload.\nAuthentication and privilege requirements depend on the specific vector; however, the vulnerability allows unauthorized retrieval of data that should otherwise be restricted.\nPost-exploitation impact includes the aggregation of sensitive operational data, internal network mapping, and the potential harvesting of static credentials or configuration secrets. These artifacts can be leveraged to mount secondary attacks against the broader Bosch ecosystem or underlying host operating systems."
}