Back to Database
Status published
High
CVE-2021-23846
B426 Credential Disclosure
Vulnerability Description
When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5, which will be released on the 30th of June, 2021.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-23846
Credits & Attribution
No credits recorded in the NVD database.
More from Bosch
View All →CVE-2025-32063
Enabling SSH server on Infotainment ECU
Medium
6.8
CVE-2025-32062
Stack Buffer Overflow leading to RCE in Bluetooth stack of Infotainment ECU
High
8.8
CVE-2025-32061
Stack Buffer Overflow leading to RCE in Bluetooth stack of Infotainment ECU
High
8.8
CVE-2025-32060
Absence of Kernel Module Signature Verification on Linux System of Infotainment ECU
Medium
6.7
CVE-2025-32059
Stack Buffer Overflow leading to RCE in Bluetooth stack of Infotainment ECU
High
8.8
Affected Vendor
Bosch
View all reports →Affected Software
B426 Firmware
Vulnerable Versions:
03.01.0004, 03.02.002, 03.05.0003, 03.03.0009
Timeline
Official Publish:
June 18th, 2021
Last Modified:
September 16th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H