First published: Mon Oct 04 2021(Updated: )
The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashing algorithm and therefore allow an attacker to determine the password by using rainbow tables.
Credit: psirt@bosch.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bosch Rexroth Indramotion Xlc Firmware | ||
Bosch Rexroth Indramotion Xlc | ||
Bosch Rexroth Indramotion Mlc Firmware | ||
Bosch Rexroth Indramotion Mlc |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2021-23855.
The severity of CVE-2021-23855 is high.
Bosch Rexroth Indramotion Xlc Firmware and Bosch Rexroth Indramotion Mlc Firmware are affected by CVE-2021-23855.
The risk associated with CVE-2021-23855 is that an attacker can determine the passwords by using rainbow tables.
To fix CVE-2021-23855, it is recommended to update the web server and use a stronger hashing algorithm to hash the passwords.