8.8

CVE-2021-23846

B426 Credential Disclosure

When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5, which will be released on the 30th of June, 2021.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BoschB426 Firmware Version03.01.0004
   BoschB426 Version-
BoschB426 Firmware Version03.02.002
   BoschB426 Version-
BoschB426 Firmware Version03.03.0009
   BoschB426 Version-
BoschB426 Firmware Version03.05.0003
   BoschB426 Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.55% 0.413
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
psirt@bosch.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-319 Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

https://psirt.bosch.com/security-advisories/bosch-sa-196933-bt.html
Vendor Advisory