CVE-2021-23858

HIGH

Bosch Rexroth IndraMotion MLC and IndraControl XLC Firmware < 12 - Unauthenticated Information Disclosure via Web Server

Title source: llm
STIX 2.1

Description

Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by another unprotected web server resource.

References (1)

Core 1
Core References

Scores

CVSS v3 8.6
EPSS 0.0120
EPSS Percentile 64.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Details

CWE
CWE-200 CWE-306
Status published
Products (12)
bosch/indracontrol_xlc_firmware < 12
bosch/rexroth_indramotion_mlc_l20_firmware < 12
bosch/rexroth_indramotion_mlc_l25_firmware < 12
bosch/rexroth_indramotion_mlc_l40_firmware < 12
bosch/rexroth_indramotion_mlc_l45_firmware < 12
bosch/rexroth_indramotion_mlc_l65_firmware < 12
bosch/rexroth_indramotion_mlc_l75_firmware < 12
bosch/rexroth_indramotion_mlc_l85_firmware < 12
bosch/rexroth_indramotion_mlc_xm21_firmware < 12
bosch/rexroth_indramotion_mlc_xm22_firmware < 12
... and 2 more
Published Oct 04, 2021
Tracked Since Feb 18, 2026