VYPR

Rexroth Indramotion Xlc Firmware

by Bosch

CVEs (2)

  • CVE-2021-23857CriOct 4, 2021
    risk 0.65cvss 10.0epss 0.01

    Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login to the system.

  • CVE-2021-23855HigOct 4, 2021
    risk 0.56cvss 8.6epss 0.01

    The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashing algorithm and therefore allow an attacker to determine the password by using rainbow tables.