CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Bosch 12Indracontrol Xlc Firmware Rexroth Indramotion Mlc L20 FirmwareRexroth Indramotion Mlc L25 Firmware+9 moreJun 17, 2026 Oct 4, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are ex...Show more |
1Bosch 12Rexroth Indramotion Mlc L20 Firmware Rexroth Indramotion Mlc L25 FirmwareRexroth Indramotion Mlc L40 Firmware+9 moreJun 17, 2026 Oct 4, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login t...Show more |
1Bosch 2Rexroth Indramotion Mlc L20 Firmware Rexroth Indramotion Mlc L40 FirmwareJun 17, 2026 Oct 4, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The web server is vulnerable to reflected XSS and therefore an attacker might be able to execute scripts on a client’s computer by sending the client a manipulated URL. |