CVE-2021-23858

EUVD-2021-10784
Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by another unprotected web server resource.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
boschCNA
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 46%
Affected Products (NVD)
VendorProductVersion
boschrexroth_indramotion_mlc_l20_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_l40_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_l25_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_l45_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_l65_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_l85_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_xm21_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_xm22_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_xm41_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_xm42_firmware
𝑥
≤ 12
boschindracontrol_xlc_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_l75_firmware
𝑥
≤ 12
𝑥
= Vulnerable software versions