CVE-2024-48989: Bosch Rexroth AG Indradrive Fwa-Indrv*-Mp*

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacker to cause a denial of service, rendering the device unresponsive by sending arbitrary UDP messages.

Affected products

  • Bosch Rexroth AG Indradrive Fwa-Indrv*-Mp*: from 17VRS, before 20V36 (fixed in 20V36)
  • Boschrexrothag Indradrive Fwa Indrv Mp: from 17vrs, before 20v36 (fixed in 20v36)

Published 2024-11-13. Last modified 2026-06-17.