PT-2021-15568 · Rexroth+1 · Indramotion Mlc Indramotion Xlc+1
Eran Jacob
+2
·
Published
2021-10-04
·
Updated
2022-08-30
·
CVE-2021-23855
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
No specific software or versions are mentioned.
Description:
The issue concerns an exposed user and password database due to an unprotected web server resource. The passwords are hashed using a weak hashing algorithm, making them susceptible to attacks using rainbow tables, which could allow an attacker to determine the password.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Indramotion Mlc Indramotion Xlc
Rexroth Indramotion Xlc Firmware