First published: Mon Oct 04 2021(Updated: )
The web server is vulnerable to reflected XSS and therefore an attacker might be able to execute scripts on a client’s computer by sending the client a manipulated URL.
Credit: psirt@bosch.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bosch Rexroth Indramotion Mlc L20 Firmware | ||
Bosch Rexroth Indramotion Mlc L20 | ||
Bosch Rexroth Indramotion Mlc L40 Firmware | ||
Bosch Rexroth Indramotion Mlc L40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-23856 is critical.
Bosch Rexroth Indramotion Mlc L20 Firmware is affected by CVE-2021-23856.
An attacker can exploit CVE-2021-23856 by sending a manipulated URL to the client.
No, Bosch Rexroth Indramotion Mlc L40 is not vulnerable to CVE-2021-23856.
More information about CVE-2021-23856 can be found at https://psirt.bosch.com/security-advisories/bosch-sa-741752.html.