Vulnerability Details CVE-2021-23846
When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5, which will be released on the 30th of June, 2021.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.5%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 4.3
Products affected by CVE-2021-23846
-
-
cpe:2.3:o:bosch:b426_firmware:03.01.0004
-
cpe:2.3:o:bosch:b426_firmware:03.02.002
-
cpe:2.3:o:bosch:b426_firmware:03.03.0009
-
cpe:2.3:o:bosch:b426_firmware:03.05.0003