Cyber Resilience

CVE-2021-23858

High

Published: 04 October 2021

Published
04 October 2021
Modified
21 November 2024
KEV Added
Patch
CVSS Score v3.1 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
EPSS Score 0.0024 47.3th percentile
Risk Priority 17 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2021-23858 is a high-severity Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) vulnerability in Bosch Rexroth Indramotion Mlc L20 Firmware. Its CVSS base score is 8.6 (High).

Operationally, ranked at the 47.3th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability details

Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by…

more

another unprotected web server resource.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

bosch
rexroth indramotion mlc l20 firmware
≤ 12
bosch
rexroth indramotion mlc l40 firmware
≤ 12
bosch
rexroth indramotion mlc l25 firmware
≤ 12
bosch
rexroth indramotion mlc l45 firmware
≤ 12
bosch
rexroth indramotion mlc l65 firmware
≤ 12
bosch
rexroth indramotion mlc l85 firmware
≤ 12
bosch
rexroth indramotion mlc xm21 firmware
≤ 12
bosch
rexroth indramotion mlc xm22 firmware
≤ 12
bosch
rexroth indramotion mlc xm41 firmware
≤ 12
bosch
rexroth indramotion mlc xm42 firmware
≤ 12
+2 more product configuration(s) — see NVD for full list

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-200 CWE-306

Session auditing enables detection of unauthorized exposure or access to sensitive information during user activities.

addresses: CWE-200 CWE-306

Privacy and security architectures require controls to protect sensitive information from unauthorized exposure across the system lifecycle.

addresses: CWE-200 CWE-306

Inventory identifies all systems holding or processing data, enabling detection of unauthorized exposure paths before exploitation.

addresses: CWE-306 CWE-200

Protection planning for critical infrastructure directly calls for authentication of access to essential functions before any operation is permitted.

addresses: CWE-306 CWE-200

Risk assessments evaluate exposure of critical functions lacking authentication and prioritize corrective controls.

addresses: CWE-306 CWE-200

Requires authentication gates on critical functions that must remain unavailable to anonymous public users.

addresses: CWE-306 CWE-200

Treats remote activation of surveillance-capable devices as a critical function that must be disabled or authenticated.

addresses: CWE-200 CWE-306

Decoys supply misleading data and log access attempts, directly detecting and deflecting unauthorized information exposure.

References