CRITICAL🇵🇱 Wersja polska

CVE-2021-23857

CVSS 10.0v3.1pub. 2021-10-04upd. 2024-11-21

Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login to the system.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Bosch Rexroth Indramotion Mlc L20

    HW
    Bosch
    all versions
  • Bosch Rexroth Indramotion Mlc L20 Firmware

    OS
    Bosch
    ≤ 12
  • Bosch Rexroth Indramotion Mlc L25

    HW
    Bosch
    all versions
  • Bosch Rexroth Indramotion Mlc L25 Firmware

    OS
    Bosch
    ≤ 12
  • Bosch Rexroth Indramotion Mlc L40

    HW
    Bosch
    all versions
  • Bosch Rexroth Indramotion Mlc L40 Firmware

    OS
    Bosch
    ≤ 12
  • Bosch Rexroth Indramotion Mlc L45

    HW
    Bosch
    all versions
  • Bosch Rexroth Indramotion Mlc L45 Firmware

    OS
    Bosch
    ≤ 12
  • Bosch Rexroth Indramotion Mlc L65

    HW
    Bosch
    all versions
  • Bosch Rexroth Indramotion Mlc L65 Firmware

    OS
    Bosch
    ≤ 12
  • Bosch Rexroth Indramotion Mlc L75

    HW
    Bosch
    all versions
  • Bosch Rexroth Indramotion Mlc L75 Firmware

    OS
    Bosch
    ≤ 12
  • Bosch Rexroth Indramotion Mlc L85

    HW
    Bosch
    all versions
  • Bosch Rexroth Indramotion Mlc L85 Firmware

    OS
    Bosch
    ≤ 12
  • Bosch Rexroth Indramotion Mlc Xm21

    HW
    Bosch
    all versions
  • Bosch Rexroth Indramotion Mlc Xm21 Firmware

    OS
    Bosch
    ≤ 12
  • Bosch Rexroth Indramotion Mlc Xm22

    HW
    Bosch
    all versions
  • Bosch Rexroth Indramotion Mlc Xm22 Firmware

    OS
    Bosch
    ≤ 12
  • Bosch Rexroth Indramotion Mlc Xm41

    HW
    Bosch
    all versions
  • Bosch Rexroth Indramotion Mlc Xm41 Firmware

    OS
    Bosch
    ≤ 12
  • Bosch Rexroth Indramotion Mlc Xm42

    HW
    Bosch
    all versions
  • Bosch Rexroth Indramotion Mlc Xm42 Firmware

    OS
    Bosch
    ≤ 12
  • Bosch Rexroth Indramotion Xlc

    HW
    Bosch
    all versions
  • Bosch Rexroth Indramotion Xlc Firmware

    OS
    Bosch
    ≤ 12
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2021-23856CRITICAL10.0PL ✓same product

Reflected XSS w serwerze web Bosch Rexroth Indramotion MLC L20/L40

CVE-2021-23855HIGH8.6same product

The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a ...

CVE-2021-23858HIGH8.6same product

Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an u...

CVE-2022-36301CRITICAL9.8PL ✓same vendor

Bosch BF-OS: brak wymuszania silnych haseł umożliwia brute-force

CVE-2021-23859CRITICAL9.1PL ✓same vendor

Bosch BVMS/VRM — nieuwierzytelniona awaria usługi i obejście autoryzacji