Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2025-24340", "assignerOrgId": "c95f66b2-7e7c-41c5-8f09-6f86ec68659c", "state": "PUBLISHED", "assignerShortName": "bosch", "dateReserved": "2025-01-20T15:09:10.532Z", "datePublished": "2025-04-30T10:59:06.633Z", "dateUpdated": "2025-04-30T15:44:38.122Z"}, "containers": {"cna": {"providerMetadata": {"orgId": "c95f66b2-7e7c-41c5-8f09-6f86ec68659c", "shortName": "bosch", "dateUpdated": "2025-04-30T10:59:06.633Z"}, "descriptions": [{"lang": "en", "value": "A vulnerability in the users configuration file of ctrlX OS may allow a remote authenticated (low-privileged) attacker to recover the plaintext passwords of other users."}], "affected": [{"vendor": "Bosch Rexroth AG", "product": "ctrlX OS - Device Admin", "versions": [{"version": "1.12.0", "status": "affected", "versionType": "custom", "lessThanOrEqual": "1.12.9"}, {"version": "1.20.0", "status": "affected", "versionType": "custom", "lessThanOrEqual": "1.20.7"}, {"version": "2.6.0", "status": "affected", "versionType": "custom", "lessThanOrEqual": "2.6.8"}]}], "problemTypes": [{"descriptions": [{"lang": "en-US", "description": "CWE-916 Use of Password Hash With Insufficient Computational Effort", "cweId": "CWE-916"}]}], "references": [{"url": "https://psirt.bosch.com/security-advisories/BOSCH-SA-640452.html", "name": "https://psirt.bosch.com/security-advisories/BOSCH-SA-640452.html", "tags": ["vendor-advisory"]}], "metrics": [{"cvssV3_1": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM"}}]}, "adp": [{"metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2025-04-30T15:44:20.325238Z", "id": "CVE-2025-24340", "options": [{"Exploitation": "none"}, {"Automatable": "no"}, {"Technical Impact": "partial"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2025-04-30T15:44:38.122Z"}}]}}