Cleartext transmission of sensitive information in Bosch Remote Programing Software (RPS) and Bosch Remote Programing Software (RPS Lite) - CVE-2023-49265
Published: March 13, 2024
Vulnerability identifier: #VU87502
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-49265
CWE-ID: CWE-319
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to gain access to sensitive information.
The vulnerability exists due to software uses insecure communication channel to transmit sensitive information. A local attacker can gain access to sensitive data.
Affected software
Bosch Remote Programing Software (RPS)
Bosch Remote Programing Software (RPS Lite)
Bosch Remote Programing Software (RPS Lite)
How to mitigate CVE-2023-49265
Install updates from vendor's website.
Bosch Remote Programing Software (RPS) - update to 6.14.100
Bosch Remote Programing Software (RPS Lite) - update to 6.14.100
Bosch Remote Programing Software (RPS Lite) - update to 6.14.100