CVE detail
CVE-2021-23858 — CVE-2021-23858
Published 2021-10-04 · Modified 2026-06-17 · Vendor bosch · Product rexroth_indramotion_mlc_l20_firmware · Source nvd
HIGH
severity
CVSS-derived band
0.0124
EPSS probability
exploitation probability, 30d
66.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by another unprotected web server resource.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References