ICSA-24-312-03
·
Published 2024-11-07
·
View on CISA ICS-CERT ↗
Bosch Rexroth IndraDrive
CVSS 7.5
HIGH
Risk Summary
Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service, rendering the device unresponsive by sending arbitrary UDP messages.
CVEs (1)
Remediations
- Bosch Rexroth has fixed this vulnerability starting with FWA-INDRV-MP-20V36. Bosch Rexroth recommends updating as soon as possible.
- In use cases in which a device update is not possible or not feasible, Bosch Rexroth recommends compensatory measures which prevent or at least complicate taking advantage of the vulnerability. Always define such compensatory measures individually, in the context of the operational environment.
- Some possible measures are described in "Security Manual Electric Drives and Controls", like network segmentation. In general, it is highly recommended to implement the measures described in "Security Manual Drives and Controls".
- For more information, refer to the Bosch PSIRT Security Advisory BOSCH-SA-315415
- Please contact the Bosch PSIRT if you have feedback, comments, or additional information about this vulnerability at: [email protected] .
Affected Vendors
Bosch Rexroth
Affected Products (1)
Bosch Rexroth
·
Bosch Rexroth AG IndraDrive FWA-INDRV-MP
17VRS<20V36
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more