CVE-2021-23857 is a critical authentication bypass vulnerability affecting Bosch products, allowing attackers to log in using a password hash instead of the actual password. This flaw, particularly dangerous when combined with CVE-2021-23858, enables unauthenticated remote attackers to achieve full compromise (confidentiality, integrity, availability) with low attack complexity. Despite its CVSS score of 9.8, there is currently no public exploit code (Metasploit, Nuclei, ExploitDB) and minimal community discussion or media coverage, indicating a low observed exploitation status.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 12CPE matchmatch criteria | cpe:2.3:o:bosch:rexroth_indramotion_mlc_l20_firmware:*:*:*:*:*:*:*:* | ||
<= 12CPE matchmatch criteria | cpe:2.3:o:bosch:rexroth_indramotion_mlc_l40_firmware:*:*:*:*:*:*:*:* | ||
<= 12CPE matchmatch criteria | cpe:2.3:o:bosch:rexroth_indramotion_mlc_l25_firmware:*:*:*:*:*:*:*:* | ||
<= 12CPE matchmatch criteria | cpe:2.3:o:bosch:rexroth_indramotion_mlc_l45_firmware:*:*:*:*:*:*:*:* | ||
<= 12CPE matchmatch criteria | cpe:2.3:o:bosch:rexroth_indramotion_mlc_l65_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple vulnerabilities in Rexroth IndraMotion and IndraLogic series
Oct 4, 2021Multiple vulnerabilities in Rexroth IndraMotion and IndraLogic series
Oct 4, 2021Multiple vulnerabilities in Rexroth IndraMotion and IndraLogic series
Oct 4, 2021Multiple vulnerabilities in Rexroth IndraMotion and IndraLogic series
Oct 4, 2021Multiple vulnerabilities in Rexroth IndraMotion and IndraLogic series
Oct 4, 2021Multiple vulnerabilities in Rexroth IndraMotion and IndraLogic series
Oct 4, 2021