CVE-2021-23858

Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by another unprotected web server resource.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
boschCNA
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
VendorProductVersion
boschrexroth_indramotion_mlc_l20_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_l40_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_l25_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_l45_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_l65_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_l85_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_xm21_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_xm22_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_xm41_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_xm42_firmware
𝑥
≤ 12
boschindracontrol_xlc_firmware
𝑥
≤ 12
boschrexroth_indramotion_mlc_l75_firmware
𝑥
≤ 12
𝑥
= Vulnerable software versions