CVE-2021-23846
18.06.2021, 14:15
When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5, which will be released on the 30th of June, 2021.Enginsight
Vendor | Product | Version |
---|---|---|
bosch | b426_firmware | 03.01.0004 |
bosch | b426_firmware | 03.02.002 |
bosch | b426_firmware | 03.03.0009 |
bosch | b426_firmware | 03.05.0003 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration