Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login to the system.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HBosch Rexroth Indramotion Mlc L20
HWBoschall versionsBosch Rexroth Indramotion Mlc L20 Firmware
OSBosch≤ 12Bosch Rexroth Indramotion Mlc L25
HWBoschall versionsBosch Rexroth Indramotion Mlc L25 Firmware
OSBosch≤ 12Bosch Rexroth Indramotion Mlc L40
HWBoschall versionsBosch Rexroth Indramotion Mlc L40 Firmware
OSBosch≤ 12Bosch Rexroth Indramotion Mlc L45
HWBoschall versionsBosch Rexroth Indramotion Mlc L45 Firmware
OSBosch≤ 12Bosch Rexroth Indramotion Mlc L65
HWBoschall versionsBosch Rexroth Indramotion Mlc L65 Firmware
OSBosch≤ 12Bosch Rexroth Indramotion Mlc L75
HWBoschall versionsBosch Rexroth Indramotion Mlc L75 Firmware
OSBosch≤ 12Bosch Rexroth Indramotion Mlc L85
HWBoschall versionsBosch Rexroth Indramotion Mlc L85 Firmware
OSBosch≤ 12Bosch Rexroth Indramotion Mlc Xm21
HWBoschall versionsBosch Rexroth Indramotion Mlc Xm21 Firmware
OSBosch≤ 12Bosch Rexroth Indramotion Mlc Xm22
HWBoschall versionsBosch Rexroth Indramotion Mlc Xm22 Firmware
OSBosch≤ 12Bosch Rexroth Indramotion Mlc Xm41
HWBoschall versionsBosch Rexroth Indramotion Mlc Xm41 Firmware
OSBosch≤ 12Bosch Rexroth Indramotion Mlc Xm42
HWBoschall versionsBosch Rexroth Indramotion Mlc Xm42 Firmware
OSBosch≤ 12Bosch Rexroth Indramotion Xlc
HWBoschall versionsBosch Rexroth Indramotion Xlc Firmware
OSBosch≤ 12
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
Related vulnerabilities
CVE-2021-23856CRITICAL10.0PL ✓same product
Reflected XSS w serwerze web Bosch Rexroth Indramotion MLC L20/L40
CVE-2021-23855HIGH8.6same product
The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a ...
CVE-2021-23858HIGH8.6same product
Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an u...
CVE-2022-36301CRITICAL9.8PL ✓same vendor
Bosch BF-OS: brak wymuszania silnych haseł umożliwia brute-force
CVE-2021-23859CRITICAL9.1PL ✓same vendor
Bosch BVMS/VRM — nieuwierzytelniona awaria usługi i obejście autoryzacji