First published: Mon Oct 04 2021(Updated: )
Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by another unprotected web server resource.
Credit: psirt@bosch.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bosch Rexroth Indramotion Mlc L20 Firmware | <=12 | |
Bosch Rexroth Indramotion Mlc L20 | ||
Bosch Rexroth Indramotion Mlc L40 Firmware | <=12 | |
Bosch Rexroth Indramotion Mlc L40 | ||
Bosch Rexroth Indramotion Mlc L25 Firmware | <=12 | |
Bosch Rexroth Indramotion Mlc L25 | ||
Bosch Rexroth Indramotion Mlc L45 Firmware | <=12 | |
Bosch Rexroth Indramotion Mlc L45 | ||
Bosch Rexroth Indramotion Mlc L65 Firmware | <=12 | |
Bosch Rexroth Indramotion Mlc L65 | ||
Bosch Rexroth Indramotion Mlc L85 Firmware | <=12 | |
Bosch Rexroth Indramotion Mlc L85 | ||
Bosch Rexroth Indramotion Mlc Xm21 Firmware | <=12 | |
Bosch Rexroth Indramotion Mlc Xm21 | ||
Bosch Rexroth Indramotion Mlc Xm22 Firmware | <=12 | |
Bosch Rexroth Indramotion Mlc Xm22 | ||
Bosch Rexroth Indramotion Mlc Xm41 Firmware | <=12 | |
Bosch Rexroth Indramotion Mlc Xm41 | ||
Bosch Rexroth Indramotion Mlc Xm42 Firmware | <=12 | |
Bosch Rexroth Indramotion Mlc Xm42 | ||
Bosch Indracontrol Xlc Firmware | <=12 | |
Bosch Indracontrol Xlc | ||
Bosch Rexroth Indramotion Mlc L75 Firmware | <=12 | |
Bosch Rexroth Indramotion Mlc L75 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23858 refers to an information disclosure vulnerability where the main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication.
The Bosch Rexroth Indramotion Mlc L20, L40, L25, L45, L65, L85, Xm21, Xm22, Xm41, and Xm42 firmwares are affected by CVE-2021-23858. The Bosch Indracontrol Xlc firmware is also affected.
CVE-2021-23858 has a severity rating of 7.5 (High).
To fix CVE-2021-23858, it is recommended to apply the necessary security updates provided by Bosch.
More information about CVE-2021-23858 can be found in the Bosch Security Advisory SA-741752 available at https://psirt.bosch.com/security-advisories/bosch-sa-741752.html.