CVE-2021-23857: Login with hash
Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login to the system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-23857?
CVE-2021-23857 is a vulnerability that allows an attacker to log in to a system using the hash of the password, instead of the password itself.
How severe is CVE-2021-23857?
CVE-2021-23857 has a severity score of 9.8, which is considered critical.
What software is affected by CVE-2021-23857?
Bosch Rexroth Indramotion Mlc L20 Firmware, Bosch Rexroth Indramotion Mlc L40 Firmware, Bosch Rexroth Indramotion Mlc L25 Firmware, Bosch Rexroth Indramotion Mlc L45 Firmware, Bosch Rexroth Indramotion Mlc L65 Firmware, Bosch Rexroth Indramotion Mlc L75 Firmware, Bosch Rexroth Indramotion Mlc L85 Firmware, Bosch Rexroth Indramotion Mlc Xm22 Firmware, Bosch Rexroth Indramotion Mlc Xm21 Firmware, Bosch Rexroth Indramotion Mlc Xm41 Firmware, Bosch Rexroth Indramotion Mlc Xm42 Firmware, Bosch Rexroth Indramotion Xlc Firmware are affected by CVE-2021-23857.
Is Bosch Rexroth Indramotion Mlc L20 affected?
Yes, Bosch Rexroth Indramotion Mlc L20 Firmware is affected by CVE-2021-23857.
How can I fix CVE-2021-23857?
To fix CVE-2021-23857, it is recommended to update the affected software to a version that includes the security patch provided by Bosch.