Standard Windows users can access the configuration file for database access of the BRAIN2 application and decrypt it.
The BRAIN2 application stores database authentication credentials in a configuration file that is accessible to standard (unprivileged) Windows user accounts. A regular user can read this file and then decrypt the passwords or other access credentials contained in it. The error is classified as CWE-260 (Password in Configuration File), indicating improper protection of credentials stored in configuration files.
An attacker with local access to the system can obtain BRAIN2 application database credentials, leading to unauthorized access to data, modification or deletion, and potentially lateral movement through the infrastructure.
Apply patches available from the vendor in accordance with the references (Bizerba SA-2025-0003 document). Additionally, it is recommended to restrict permissions to the configuration file at the Windows file system level and immediately change compromised database credentials.
Bizerba BRAIN2 application running on Windows — specific versions indicated in vendor references (bizerba.com)
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H