← Back

CVE-2021-23846

nvd nist
Published: Jun 18, 2021Modified: Nov 21, 2024

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5, which will be released on the 30th of June, 2021.

Affected (4)

Products: Bosch: B426 Firmware
1 product
B426 Firmware
Configuration A
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Bosch
Version 03.01.0004
Version 03.02.002
Version 03.03.0009
Version 03.05.0003
Running on/withPlatform Versions
Bosch
B426
All versions

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.