Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2021-23858 Details
Description
Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by another unprotected web server resource.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://psirt.bosch.com/security-advisories/bosch-sa-741752.html | CVE | Vendor Advisory |
| https://psirt.bosch.com/security-advisories/bosch-sa-741752.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| bosch rexroth indramotion mlc l20 firmware | <= 12 |
CPE
Remediation
| |
| bosch rexroth indramotion mlc l20 | All versions |
CPE
Remediation
| |
| bosch rexroth indramotion mlc l40 firmware | <= 12 |
CPE
Remediation
| |
| bosch rexroth indramotion mlc l40 | All versions |
CPE
Remediation
| |
| bosch rexroth indramotion mlc l25 firmware | <= 12 |
CPE
Remediation
| |
| bosch rexroth indramotion mlc l25 | All versions |
CPE
Remediation
| |
| bosch rexroth indramotion mlc l45 firmware | <= 12 |
CPE
Remediation
| |
| bosch rexroth indramotion mlc l45 | All versions |
CPE
Remediation
| |
| bosch rexroth indramotion mlc l65 firmware | <= 12 |
CPE
Remediation
| |
| bosch rexroth indramotion mlc l65 | All versions |
CPE
Remediation
| |
| bosch rexroth indramotion mlc l85 firmware | <= 12 |
CPE
Remediation
| |
| bosch rexroth indramotion mlc l85 | All versions |
CPE
Remediation
| |
| bosch rexroth indramotion mlc xm21 firmware | <= 12 |
CPE
Remediation
| |
| bosch rexroth indramotion mlc xm21 | All versions |
CPE
Remediation
| |
| bosch rexroth indramotion mlc xm22 firmware | <= 12 |
CPE
Remediation
| |
| bosch rexroth indramotion mlc xm22 | All versions |
CPE
Remediation
| |
| bosch rexroth indramotion mlc xm41 firmware | <= 12 |
CPE
Remediation
| |
| bosch rexroth indramotion mlc xm41 | All versions |
CPE
Remediation
| |
| bosch rexroth indramotion mlc xm42 firmware | <= 12 |
CPE
Remediation
| |
| bosch rexroth indramotion mlc xm42 | All versions |
CPE
Remediation
| |
| bosch indracontrol xlc firmware | <= 12 |
CPE
Remediation
| |
| bosch indracontrol xlc | All versions |
CPE
Remediation
| |
| bosch rexroth indramotion mlc l75 firmware | <= 12 |
CPE
Remediation
| |
| bosch rexroth indramotion mlc l75 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Aug 30, 2022 | Reanalysis | [email protected] |
| Oct 14, 2021 | Initial Analysis | [email protected] |