CVE-2025-24339: Medium severity bosch ctrlx os vulnerability
Published Apr 30, 2025
·Updated
A vulnerability in the web application of ctrlX OS allows a remote unauthenticated attacker to conduct various attacks against users of the vulnerable system, including web cache poisoning or Man-in-the-Middle (MitM), via a crafted HTTP request.
Affected Software
1 affected component
Bosch ctrlX OS
Event History
Apr 30, 2025
CVE Published
via MITRE·10:54 AM
Data Sourced
via MITRE·10:54 AM
DescriptionSeverity
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-24339?
CVE-2025-24339 is considered a high-severity vulnerability due to its potential for remote exploitation.
2
How do I fix CVE-2025-24339?
To fix CVE-2025-24339, update the Bosch ctrlX OS to the latest patched version provided by the vendor.
3
Who is affected by CVE-2025-24339?
Any user of the Bosch ctrlX OS with accessible web applications is potentially affected by CVE-2025-24339.
4
What types of attacks can be executed due to CVE-2025-24339?
CVE-2025-24339 can lead to web cache poisoning and Man-in-the-Middle (MitM) attacks.
5
Is CVE-2025-24339 exploitable without authentication?
Yes, CVE-2025-24339 can be exploited by remote unauthenticated attackers.