PatchSiren

Bosch Rexroth AG CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Bosch Rexroth AG CVE published 2024-11-07

CVE-2024-48989

A vulnerability in the PROFINET stack implementation of Bosch Rexroth IndraDrive allows remote attackers to cause denial-of-service by sending arbitrary UDP messages, rendering affected devices unresponsive. The vulnerability affects IndraDrive firmware versions prior to FWA-INDRV-MP-20V36. Bosch Rexroth has released a fixed version and recommends updating as soon as possible. For environments where patch [truncated]