← Voltar para CVEs
CVE-2021-23857
CRITICAL10.0
Descricao
Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login to the system.
Detalhes CVE
Pontuacao CVSS v3.110.0
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado10/4/2021
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0
Produtos afetados
bosch:rexroth_indramotion_mlc_l20bosch:rexroth_indramotion_mlc_l20_firmwarebosch:rexroth_indramotion_mlc_l25bosch:rexroth_indramotion_mlc_l25_firmwarebosch:rexroth_indramotion_mlc_l40bosch:rexroth_indramotion_mlc_l40_firmwarebosch:rexroth_indramotion_mlc_l45bosch:rexroth_indramotion_mlc_l45_firmwarebosch:rexroth_indramotion_mlc_l65bosch:rexroth_indramotion_mlc_l65_firmwarebosch:rexroth_indramotion_mlc_l75bosch:rexroth_indramotion_mlc_l75_firmwarebosch:rexroth_indramotion_mlc_l85bosch:rexroth_indramotion_mlc_l85_firmwarebosch:rexroth_indramotion_mlc_xm21bosch:rexroth_indramotion_mlc_xm21_firmwarebosch:rexroth_indramotion_mlc_xm22bosch:rexroth_indramotion_mlc_xm22_firmwarebosch:rexroth_indramotion_mlc_xm41bosch:rexroth_indramotion_mlc_xm41_firmwarebosch:rexroth_indramotion_mlc_xm42bosch:rexroth_indramotion_mlc_xm42_firmwarebosch:rexroth_indramotion_xlcbosch:rexroth_indramotion_xlc_firmware
Fraquezas (CWE)
CWE-836CWE-287
Referencias
https://psirt.bosch.com/security-advisories/bosch-sa-741752.html(psirt@bosch.com)
https://psirt.bosch.com/security-advisories/bosch-sa-741752.html(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.