605
VMScore

CVE-2021-23845

Published: 18/06/2021 Updated: 24/06/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

This vulnerability could allow an malicious user to hijack a session while a user is logged in the configuration web page. This vulnerability exists by a security researcher in B426 and found during internal product tests in B426-CN/B429-CN, and B426-M and has been fixed already starting from version 3.08 on, which was released on June 2019.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bosch b426_firmware

bosch b426-cn_firmware

bosch b429-cn_firmware

bosch b426-m_firmware