Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by another unprotected web server resource.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:NBosch Indracontrol Xlc
HWBoschwszystkie wersjeBosch Indracontrol Xlc Firmware
OSBosch≤ 12Bosch Rexroth Indramotion Mlc L20
HWBoschwszystkie wersjeBosch Rexroth Indramotion Mlc L20 Firmware
OSBosch≤ 12Bosch Rexroth Indramotion Mlc L25
HWBoschwszystkie wersjeBosch Rexroth Indramotion Mlc L25 Firmware
OSBosch≤ 12Bosch Rexroth Indramotion Mlc L40
HWBoschwszystkie wersjeBosch Rexroth Indramotion Mlc L40 Firmware
OSBosch≤ 12Bosch Rexroth Indramotion Mlc L45
HWBoschwszystkie wersjeBosch Rexroth Indramotion Mlc L45 Firmware
OSBosch≤ 12Bosch Rexroth Indramotion Mlc L65
HWBoschwszystkie wersjeBosch Rexroth Indramotion Mlc L65 Firmware
OSBosch≤ 12Bosch Rexroth Indramotion Mlc L75
HWBoschwszystkie wersjeBosch Rexroth Indramotion Mlc L75 Firmware
OSBosch≤ 12Bosch Rexroth Indramotion Mlc L85
HWBoschwszystkie wersjeBosch Rexroth Indramotion Mlc L85 Firmware
OSBosch≤ 12Bosch Rexroth Indramotion Mlc Xm21
HWBoschwszystkie wersjeBosch Rexroth Indramotion Mlc Xm21 Firmware
OSBosch≤ 12Bosch Rexroth Indramotion Mlc Xm22
HWBoschwszystkie wersjeBosch Rexroth Indramotion Mlc Xm22 Firmware
OSBosch≤ 12Bosch Rexroth Indramotion Mlc Xm41
HWBoschwszystkie wersjeBosch Rexroth Indramotion Mlc Xm41 Firmware
OSBosch≤ 12Bosch Rexroth Indramotion Mlc Xm42
HWBoschwszystkie wersjeBosch Rexroth Indramotion Mlc Xm42 Firmware
OSBosch≤ 12
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Powiązane podatności
CVE-2021-23856CRITICAL10.0PL ✓ten sam produkt
Reflected XSS w serwerze web Bosch Rexroth Indramotion MLC L20/L40
CVE-2021-23857CRITICAL10.0PL ✓ten sam produkt
Auth Bypass poprzez logowanie hashem hasła w Bosch Rexroth IndraMotion MLC
CVE-2022-36301CRITICAL9.8PL ✓ten sam vendor
Bosch BF-OS: brak wymuszania silnych haseł umożliwia brute-force
CVE-2021-23859CRITICAL9.1PL ✓ten sam vendor
Bosch BVMS/VRM — nieuwierzytelniona awaria usługi i obejście autoryzacji
CVE-2021-23847CRITICAL9.8PL ✓ten sam vendor
Pominięcie uwierzytelniania w kamerach IP Bosch CPP6/CPP7