HIGH · 8.6

CVE-2021-23855

The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashing algorithm and therefore allow an attacker to determine the password by using ...

Vulnerability Description

The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashing algorithm and therefore allow an attacker to determine the password by using rainbow tables.

CVSS Score

8.6

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
BoschRexroth Indramotion Xlc Firmware-
BoschRexroth Indramotion Xlc-
BoschRexroth Indramotion Mlc Firmware-
BoschRexroth Indramotion Mlc-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-23855?

CVE-2021-23855 is a vulnerability with a CVSS score of 8.6 (HIGH). The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashing algorithm and therefore allow an attacker to determine the password by using ...

How severe is CVE-2021-23855?

CVE-2021-23855 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-23855?

Check the references section above for vendor advisories and patch information. Affected products include: Bosch Rexroth Indramotion Xlc Firmware, Bosch Rexroth Indramotion Xlc, Bosch Rexroth Indramotion Mlc Firmware, Bosch Rexroth Indramotion Mlc.