VYPR
High severity8.8NVD Advisory· Published Jun 18, 2021· Updated Jun 17, 2026

CVE-2021-23846

CVE-2021-23846

Description

When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5, which will be released on the 30th of June, 2021.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:o:bosch:b426_firmware:03.01.0004:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:o:bosch:b426_firmware:03.01.0004:*:*:*:*:*:*:*
    • cpe:2.3:o:bosch:b426_firmware:03.02.002:*:*:*:*:*:*:*
    • cpe:2.3:o:bosch:b426_firmware:03.03.0009:*:*:*:*:*:*:*
    • cpe:2.3:o:bosch:b426_firmware:03.05.0003:*:*:*:*:*:*:*
    • (no CPE)range: 03.01.0004
  • Bosch/BTllm-create
    Range: >=3.11.5

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.