Home / Early Warning / Vulnerabilidades / CVE-2021-23846

CVE-2021-23846

Type: 
Unavailable / Other
Severity: 
Medium
Publication date: 
06/18/2021
Last modified: 
06/24/2021
Description
When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5, which will be released on the 30th of June, 2021.
Impact
Access Vector: Through network
Access Complexity: Media
Authentication: Not required to exploit
Impact Type: No impact on system integrity + Partially affects on system confidentiality + No impact on system availability
Vulnerable software and versions
  • cpe:2.3:o:bosch:b426_firmware:03.01.0004:*:*:*:*:*:*:*
  • cpe:2.3:h:bosch:b426:-:*:*:*:*:*:*:*
To consult the complete list of products and versions see this page
References to Advisories, Solutions, and Tools
Explanation of fields