First published: Mon Oct 04 2021(Updated: )
Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login to the system.
Credit: psirt@bosch.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bosch Rexroth Indramotion Mlc L20 Firmware | <=12 | |
Bosch Rexroth Indramotion Mlc L20 | ||
Bosch Rexroth Indramotion Mlc L40 Firmware | <=12 | |
Bosch Rexroth Indramotion Mlc L40 | ||
Bosch Rexroth Indramotion Mlc L25 Firmware | <=12 | |
Bosch Rexroth Indramotion Mlc L25 | ||
Bosch Rexroth Indramotion Mlc L45 Firmware | <=12 | |
Bosch Rexroth Indramotion Mlc L45 | ||
Bosch Rexroth Indramotion Mlc L65 Firmware | <=12 | |
Bosch Rexroth Indramotion Mlc L65 | ||
Bosch Rexroth Indramotion Mlc L75 Firmware | <=12 | |
Bosch Rexroth Indramotion Mlc L75 | ||
Bosch Rexroth Indramotion Mlc L85 Firmware | <=12 | |
Bosch Rexroth Indramotion Mlc L85 | ||
Bosch Rexroth Indramotion Mlc Xm22 Firmware | <=12 | |
Bosch Rexroth Indramotion Mlc Xm22 | ||
Bosch Rexroth Indramotion Mlc Xm21 Firmware | <=12 | |
Bosch Rexroth Indramotion Mlc Xm21 | ||
Bosch Rexroth Indramotion Mlc Xm41 Firmware | <=12 | |
Bosch Rexroth Indramotion Mlc Xm41 | ||
Bosch Rexroth Indramotion Mlc Xm42 Firmware | <=12 | |
Bosch Rexroth Indramotion Mlc Xm42 | ||
Bosch Rexroth Indramotion Xlc Firmware | <=12 | |
Bosch Rexroth Indramotion Xlc |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23857 is a vulnerability that allows an attacker to log in to a system using the hash of the password, instead of the password itself.
CVE-2021-23857 has a severity score of 9.8, which is considered critical.
Bosch Rexroth Indramotion Mlc L20 Firmware, Bosch Rexroth Indramotion Mlc L40 Firmware, Bosch Rexroth Indramotion Mlc L25 Firmware, Bosch Rexroth Indramotion Mlc L45 Firmware, Bosch Rexroth Indramotion Mlc L65 Firmware, Bosch Rexroth Indramotion Mlc L75 Firmware, Bosch Rexroth Indramotion Mlc L85 Firmware, Bosch Rexroth Indramotion Mlc Xm22 Firmware, Bosch Rexroth Indramotion Mlc Xm21 Firmware, Bosch Rexroth Indramotion Mlc Xm41 Firmware, Bosch Rexroth Indramotion Mlc Xm42 Firmware, Bosch Rexroth Indramotion Xlc Firmware are affected by CVE-2021-23857.
Yes, Bosch Rexroth Indramotion Mlc L20 Firmware is affected by CVE-2021-23857.
To fix CVE-2021-23857, it is recommended to update the affected software to a version that includes the security patch provided by Bosch.