CVE-2021-23857

Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login to the system.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
boschCNA
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
VendorProductVersion
boschrexroth_indramotion_mlc_l20_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_l40_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_l25_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_l45_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_l65_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_l75_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_l85_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_xm22_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_xm21_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_xm41_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_xm42_firmware
𝑥
≤ 12
boschrexroth_indramotion_xlc_firmware
𝑥
≤ 12
𝑥
= Vulnerable software versions