4.3
CVSSv2

CVE-2021-23846

Published: 18/06/2021 Updated: 24/06/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

This vulnerability allows network-adjacent malicious users to disclose sensitive information on affected installations of Bosch B426. User interaction is required to exploit this vulnerability. The specific flaw exists within the handling of login credentials provided to the login.cgi endpoint. The issue results from displaying sensitive information in plaintext. An attacker can leverage this vulnerability to disclose sensitive information in the context of the user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bosch b426_firmware 03.01.0004

bosch b426_firmware 03.02.002

bosch b426_firmware 03.03.0009

bosch b426_firmware 03.05.0003