Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by another unprotected web server resource.

Project Subscriptions

Vendors Products
Indracontrol Xlc Subscribe
Indracontrol Xlc Firmware Subscribe
Rexroth Indramotion Mlc L20 Subscribe
Rexroth Indramotion Mlc L20 Firmware Subscribe
Rexroth Indramotion Mlc L25 Subscribe
Rexroth Indramotion Mlc L25 Firmware Subscribe
Rexroth Indramotion Mlc L40 Subscribe
Rexroth Indramotion Mlc L40 Firmware Subscribe
Rexroth Indramotion Mlc L45 Subscribe
Rexroth Indramotion Mlc L45 Firmware Subscribe
Rexroth Indramotion Mlc L65 Subscribe
Rexroth Indramotion Mlc L65 Firmware Subscribe
Rexroth Indramotion Mlc L75 Subscribe
Rexroth Indramotion Mlc L75 Firmware Subscribe
Rexroth Indramotion Mlc L85 Subscribe
Rexroth Indramotion Mlc L85 Firmware Subscribe
Rexroth Indramotion Mlc Xm21 Subscribe
Rexroth Indramotion Mlc Xm21 Firmware Subscribe
Rexroth Indramotion Mlc Xm22 Subscribe
Rexroth Indramotion Mlc Xm22 Firmware Subscribe
Rexroth Indramotion Mlc Xm41 Subscribe
Rexroth Indramotion Mlc Xm41 Firmware Subscribe
Rexroth Indramotion Mlc Xm42 Subscribe
Rexroth Indramotion Mlc Xm42 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-10784 Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by another unprotected web server resource.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: bosch

Published:

Updated: 2024-08-03T19:14:09.398Z

Reserved: 2021-01-12T00:00:00

Link: CVE-2021-23858

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-04T18:15:07.987

Modified: 2024-11-21T05:51:57.813

Link: CVE-2021-23858

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses