8.8
CVE-2021-23846
- EPSS 0.14%
- Veröffentlicht 18.06.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 05:51:56
- Quelle psirt@bosch.com
- CVE-Watchlists
- Unerledigt
When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5, which will be released on the 30th of June, 2021.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bosch ≫ B426 Firmware Version03.01.0004
Bosch ≫ B426 Firmware Version03.02.002
Bosch ≫ B426 Firmware Version03.03.0009
Bosch ≫ B426 Firmware Version03.05.0003
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.34 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
| psirt@bosch.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-319 Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.