The web server is vulnerable to reflected XSS and therefore an attacker might be able to execute scripts on a client’s computer by sending the client a manipulated URL.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HBosch Rexroth Indramotion Mlc L20
HWBoschall versionsBosch Rexroth Indramotion Mlc L20 Firmware
OSBoschall versionsBosch Rexroth Indramotion Mlc L40
HWBoschall versionsBosch Rexroth Indramotion Mlc L40 Firmware
OSBoschall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
Related vulnerabilities
CVE-2021-23857CRITICAL10.0PL ✓same product
Auth Bypass poprzez logowanie hashem hasła w Bosch Rexroth IndraMotion MLC
CVE-2021-23858HIGH8.6same product
Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an u...
CVE-2022-36301CRITICAL9.8PL ✓same vendor
Bosch BF-OS: brak wymuszania silnych haseł umożliwia brute-force
CVE-2021-23859CRITICAL9.1PL ✓same vendor
Bosch BVMS/VRM — nieuwierzytelniona awaria usługi i obejście autoryzacji
CVE-2021-23847CRITICAL9.8PL ✓same vendor
Pominięcie uwierzytelniania w kamerach IP Bosch CPP6/CPP7