Lucene search

K
cve[email protected]CVE-2021-23846
HistoryJun 18, 2021 - 2:15 p.m.

CVE-2021-23846

2021-06-1814:15:07
CWE-319
web.nvd.nist.gov
23
cve-2021-23846
http protocol
clear text transmission
mitm attack
firmware update

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

5.7 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.2%

When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5, which will be released on the 30th of June, 2021.

Affected configurations

NVD
Node
boschb426_firmwareMatch03.01.0004
OR
boschb426_firmwareMatch03.02.002
OR
boschb426_firmwareMatch03.03.0009
OR
boschb426_firmwareMatch03.05.0003
AND
boschb426Match-

CNA Affected

[
  {
    "product": "B426Β Firmware",
    "vendor": "Bosch",
    "versions": [
      {
        "status": "affected",
        "version": "03.01.0004"
      },
      {
        "status": "affected",
        "version": "03.02.002"
      },
      {
        "status": "affected",
        "version": "03.05.0003"
      },
      {
        "status": "affected",
        "version": "03.03.0009"
      }
    ]
  }
]

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

5.7 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.2%

Related for CVE-2021-23846