Home

Description

Ambiguous wording in the web interface of the ctrlX OS setup mechanism could lead the user to believe that the backup file is encrypted when a password is set. However, only the private key - if available in the backup - is encrypted, while the backup file itself remains unencrypted.

PUBLISHED Reserved 2025-05-27 | Published 2025-08-14 | Updated 2025-08-14 | Assigner bosch




HIGH: 7.1CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Problem types

CWE-1104 Use of Unmaintained Third Party Components

CWE-311 Missing Encryption of Sensitive Data

Product status

1.20.0
affected

2.6.0
affected

3.6.0
affected

References

psirt.bosch.com/security-advisories/BOSCH-SA-129652.html vendor-advisory

cve.org (CVE-2025-48862)

nvd.nist.gov (CVE-2025-48862)

Download JSON