Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by another unprotected web server resource.
References
Link | Resource |
---|---|
https://psirt.bosch.com/security-advisories/bosch-sa-741752.html | Vendor Advisory |
https://psirt.bosch.com/security-advisories/bosch-sa-741752.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
History
21 Nov 2024, 05:51
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 7.8
v3 : 8.6 |
References | () https://psirt.bosch.com/security-advisories/bosch-sa-741752.html - Vendor Advisory |
30 Aug 2022, 18:18
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-306 |
14 Oct 2021, 16:45
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-522 | |
CVSS |
v2 : v3 : |
v2 : 7.8
v3 : 7.5 |
References | (CONFIRM) https://psirt.bosch.com/security-advisories/bosch-sa-741752.html - Vendor Advisory | |
CPE | cpe:2.3:h:bosch:rexroth_indramotion_mlc_l20:-:*:*:*:*:*:*:* cpe:2.3:h:bosch:rexroth_indramotion_mlc_l85:-:*:*:*:*:*:*:* cpe:2.3:o:bosch:rexroth_indramotion_mlc_l20_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:bosch:rexroth_indramotion_mlc_l25:-:*:*:*:*:*:*:* cpe:2.3:h:bosch:rexroth_indramotion_mlc_l65:-:*:*:*:*:*:*:* cpe:2.3:o:bosch:rexroth_indramotion_mlc_l45_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:bosch:rexroth_indramotion_mlc_l25_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:bosch:rexroth_indramotion_mlc_l75_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:bosch:rexroth_indramotion_mlc_xm42:-:*:*:*:*:*:*:* cpe:2.3:h:bosch:rexroth_indramotion_mlc_xm21:-:*:*:*:*:*:*:* cpe:2.3:o:bosch:rexroth_indramotion_mlc_l40_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:bosch:rexroth_indramotion_mlc_xm41:-:*:*:*:*:*:*:* cpe:2.3:o:bosch:rexroth_indramotion_mlc_l85_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:bosch:rexroth_indramotion_mlc_xm41_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:bosch:rexroth_indramotion_mlc_l45:-:*:*:*:*:*:*:* cpe:2.3:h:bosch:indracontrol_xlc:-:*:*:*:*:*:*:* cpe:2.3:h:bosch:rexroth_indramotion_mlc_l40:-:*:*:*:*:*:*:* cpe:2.3:h:bosch:rexroth_indramotion_mlc_l75:-:*:*:*:*:*:*:* cpe:2.3:o:bosch:rexroth_indramotion_mlc_xm21_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:bosch:rexroth_indramotion_mlc_xm42_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:bosch:rexroth_indramotion_mlc_l65_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:bosch:indracontrol_xlc_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:bosch:rexroth_indramotion_mlc_xm22_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:bosch:rexroth_indramotion_mlc_xm22:-:*:*:*:*:*:*:* |
04 Oct 2021, 18:18
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-10-04 18:15
Updated : 2024-11-21 05:51
NVD link : CVE-2021-23858
Mitre link : CVE-2021-23858
CVE.ORG link : CVE-2021-23858
JSON object : View
Products Affected
bosch
- rexroth_indramotion_mlc_xm41
- rexroth_indramotion_mlc_xm42
- indracontrol_xlc
- rexroth_indramotion_mlc_l75_firmware
- rexroth_indramotion_mlc_l45
- rexroth_indramotion_mlc_l20
- rexroth_indramotion_mlc_xm22_firmware
- rexroth_indramotion_mlc_l25_firmware
- rexroth_indramotion_mlc_l65_firmware
- rexroth_indramotion_mlc_l40_firmware
- rexroth_indramotion_mlc_l85_firmware
- rexroth_indramotion_mlc_l25
- rexroth_indramotion_mlc_xm21
- rexroth_indramotion_mlc_xm22
- rexroth_indramotion_mlc_l85
- indracontrol_xlc_firmware
- rexroth_indramotion_mlc_l65
- rexroth_indramotion_mlc_l20_firmware
- rexroth_indramotion_mlc_l40
- rexroth_indramotion_mlc_l45_firmware
- rexroth_indramotion_mlc_l75
- rexroth_indramotion_mlc_xm21_firmware
- rexroth_indramotion_mlc_xm42_firmware
- rexroth_indramotion_mlc_xm41_firmware