Vulnerability Details CVE-2025-60038
A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires user interaction, specifically opening a specially crafted file, which then causes the application to deserialize the malicious data, enabling Remote Code Execution (RCE). This can lead to a complete compromise of the system running Rexroth IndraWorks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 20.7%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2025-60038
-
cpe:2.3:a:bosch:rexroth_indraworks:15v06
-
cpe:2.3:a:bosch:rexroth_indraworks:15v08
-
cpe:2.3:a:bosch:rexroth_indraworks:15v10
-
cpe:2.3:a:bosch:rexroth_indraworks:15v12
-
cpe:2.3:a:bosch:rexroth_indraworks:15v14
-
cpe:2.3:a:bosch:rexroth_indraworks:15v16
-
cpe:2.3:a:bosch:rexroth_indraworks:15v18
-
cpe:2.3:a:bosch:rexroth_indraworks:15v20
-
cpe:2.3:a:bosch:rexroth_indraworks:15v22
-
cpe:2.3:a:bosch:rexroth_indraworks:15v24