CVE-2021-23845
18.06.2021, 14:15
This vulnerability could allow an attacker to hijack a session while a user is logged in the configuration web page. This vulnerability was discovered by a security researcher in B426 and found during internal product tests in B426-CN/B429-CN, and B426-M and has been fixed already starting from version 3.08 on, which was released on June 2019.Enginsight
Vendor | Product | Version |
---|---|---|
bosch | b426_firmware | 𝑥 < 03.08 |
bosch | b426-cn_firmware | 𝑥 < 03.08 |
bosch | b429-cn_firmware | 𝑥 < 03.08 |
bosch | b426-m_firmware | 𝑥 < 03.10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration