10
CVSSv2

CVE-2021-23857

Published: 04/10/2021 Updated: 30/08/2022
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an malicious user to subsequently login to the system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bosch rexroth_indramotion_mlc_l20_firmware

bosch rexroth_indramotion_mlc_l40_firmware

bosch rexroth_indramotion_mlc_l25_firmware

bosch rexroth_indramotion_mlc_l45_firmware

bosch rexroth_indramotion_mlc_l65_firmware

bosch rexroth_indramotion_mlc_l75_firmware

bosch rexroth_indramotion_mlc_l85_firmware

bosch rexroth_indramotion_mlc_xm22_firmware

bosch rexroth_indramotion_mlc_xm21_firmware

bosch rexroth_indramotion_mlc_xm41_firmware

bosch rexroth_indramotion_mlc_xm42_firmware

bosch rexroth_indramotion_xlc_firmware