CVE-2024-48989
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-48989 is a newly disclosed vulnerability that affects Bosch Rexroth's IndraDrive series of devices, which use the PROFINET stack. An attacker can exploit this issue by sending arbitrary UDP messages, leading to a denial-of-service condition and rendering the device unresponsive. This vulnerability poses a significant risk to industrial automation systems that rely on the IndraDrive devices, as it can cause operational disruptions and potentially allow further unauthorized access. Bosch Rexroth has not yet released a patch for this issue, so affected organizations should take immediate steps to mitigate the risk, such as implementing network segmentation and access controls.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.