CVE-2021-23855: Information disclosure
Published Oct 4, 2021
·Updated
The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashing algorithm and therefore allow an attacker to determine the password by using rainbow tables.
Affected Software
4 affected components
Bosch Rexroth Indramotion Xlc Firmware
Bosch Rexroth Indramotion Xlc
Bosch Rexroth Indramotion Mlc Firmware
Bosch Rexroth Indramotion Mlc
Event History
Oct 4, 2021
CVE Published
via MITRE·05:32 PM
Data Sourced
via MITRE·05:32 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-23855.
2
What is the severity of CVE-2021-23855?
The severity of CVE-2021-23855 is high.
3
Which software is affected by CVE-2021-23855?
Bosch Rexroth Indramotion Xlc Firmware and Bosch Rexroth Indramotion Mlc Firmware are affected by CVE-2021-23855.
4
What is the risk associated with CVE-2021-23855?
The risk associated with CVE-2021-23855 is that an attacker can determine the passwords by using rainbow tables.
5
How can I fix CVE-2021-23855?
To fix CVE-2021-23855, it is recommended to update the web server and use a stronger hashing algorithm to hash the passwords.