Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by another unprotected web server resource.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Bosch
Subscribe
|
Indracontrol Xlc
Subscribe
Indracontrol Xlc Firmware
Subscribe
Rexroth Indramotion Mlc L20
Subscribe
Rexroth Indramotion Mlc L20 Firmware
Subscribe
Rexroth Indramotion Mlc L25
Subscribe
Rexroth Indramotion Mlc L25 Firmware
Subscribe
Rexroth Indramotion Mlc L40
Subscribe
Rexroth Indramotion Mlc L40 Firmware
Subscribe
Rexroth Indramotion Mlc L45
Subscribe
Rexroth Indramotion Mlc L45 Firmware
Subscribe
Rexroth Indramotion Mlc L65
Subscribe
Rexroth Indramotion Mlc L65 Firmware
Subscribe
Rexroth Indramotion Mlc L75
Subscribe
Rexroth Indramotion Mlc L75 Firmware
Subscribe
Rexroth Indramotion Mlc L85
Subscribe
Rexroth Indramotion Mlc L85 Firmware
Subscribe
Rexroth Indramotion Mlc Xm21
Subscribe
Rexroth Indramotion Mlc Xm21 Firmware
Subscribe
Rexroth Indramotion Mlc Xm22
Subscribe
Rexroth Indramotion Mlc Xm22 Firmware
Subscribe
Rexroth Indramotion Mlc Xm41
Subscribe
Rexroth Indramotion Mlc Xm41 Firmware
Subscribe
Rexroth Indramotion Mlc Xm42
Subscribe
Rexroth Indramotion Mlc Xm42 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-10784 | Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by another unprotected web server resource. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: bosch
Published:
Updated: 2024-08-03T19:14:09.398Z
Reserved: 2021-01-12T00:00:00
Link: CVE-2021-23858
No data.
Status : Modified
Published: 2021-10-04T18:15:07.987
Modified: 2024-11-21T05:51:57.813
Link: CVE-2021-23858
No data.
OpenCVE Enrichment
No data.
EUVD