CVE-2021-23857
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login to the system.
Affected (12)
Products: Bosch: Rexroth Indramotion Mlc L20 Firmware, Rexroth Indramotion Mlc L40 Firmware, Rexroth Indramotion Mlc L25 Firmware, Rexroth Indramotion Mlc L45 Firmware, Rexroth Indramotion Mlc L65 Firmware, Rexroth Indramotion Mlc L75 Firmware, Rexroth Indramotion Mlc L85 Firmware, Rexroth Indramotion Mlc Xm22 Firmware, Rexroth Indramotion Mlc Xm21 Firmware, Rexroth Indramotion Mlc Xm41 Firmware, Rexroth Indramotion Mlc Xm42 Firmware, Rexroth Indramotion Xlc Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 12 |
| Running on/with | Platform Versions |
|---|---|
Bosch Rexroth Indramotion Mlc L20 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 12 |
| Running on/with | Platform Versions |
|---|---|
Bosch Rexroth Indramotion Mlc L40 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 12 |
| Running on/with | Platform Versions |
|---|---|
Bosch Rexroth Indramotion Mlc L25 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 12 |
| Running on/with | Platform Versions |
|---|---|
Bosch Rexroth Indramotion Mlc L45 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 12 |
| Running on/with | Platform Versions |
|---|---|
Bosch Rexroth Indramotion Mlc L65 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 12 |
| Running on/with | Platform Versions |
|---|---|
Bosch Rexroth Indramotion Mlc L75 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 12 |
| Running on/with | Platform Versions |
|---|---|
Bosch Rexroth Indramotion Mlc L85 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 12 |
| Running on/with | Platform Versions |
|---|---|
Bosch Rexroth Indramotion Mlc Xm22 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 12 |
| Running on/with | Platform Versions |
|---|---|
Bosch Rexroth Indramotion Mlc Xm21 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 12 |
| Running on/with | Platform Versions |
|---|---|
Bosch Rexroth Indramotion Mlc Xm41 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 12 |
| Running on/with | Platform Versions |
|---|---|
Bosch Rexroth Indramotion Mlc Xm42 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 12 |
| Running on/with | Platform Versions |
|---|---|
Bosch Rexroth Indramotion Xlc | All versions |
Related CWEs
CWE-287
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-836
Use of Password Hash Instead of Password for Authentication
The product records password hashes in a data store, receives a hash of a password from a client, and compares the supplied hash to the hash obtained from the data store.
References (2)
Source: psirt@bosch.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.