CVE-2021-23858: Information disclosure
Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by another unprotected web server resource.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-23858?
CVE-2021-23858 refers to an information disclosure vulnerability where the main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication.
What software is affected by CVE-2021-23858?
The Bosch Rexroth Indramotion Mlc L20, L40, L25, L45, L65, L85, Xm21, Xm22, Xm41, and Xm42 firmwares are affected by CVE-2021-23858. The Bosch Indracontrol Xlc firmware is also affected.
What is the severity of CVE-2021-23858?
CVE-2021-23858 has a severity rating of 7.5 (High).
How can I fix CVE-2021-23858?
To fix CVE-2021-23858, it is recommended to apply the necessary security updates provided by Bosch.
Where can I find more information about CVE-2021-23858?
More information about CVE-2021-23858 can be found in the Bosch Security Advisory SA-741752 available at https://psirt.bosch.com/security-advisories/bosch-sa-741752.html.