← Back to browse · API

CVE-2021-23857

Severity
CRITICAL
CVSS
10.0
EPSS
0.01234
Risk score
40.43
CISA KEV
No
PoC
No
Published
2021-10-04
Modified
2024-08-03
First seen
2026-08-08
Aliases
EUVD-2021-10783, GHSA-RPJW-WQ4M-V5J8
Products
Rexroth:IndraMotion MLC L20, L40 12 VRS <unspecified, Rexroth:IndraMotion MLC L25, L45, L65, L75, L85, XM21, XM22, XM41 and XM42 IndraMotion XLC 12 VRS <unspecified
Sources
euvd EUVD-2021-10783

Description

Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login to the system.

References