When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obtained by an attacker through a MITM attack. This will be fixed starting from Firmware version 3.11.5, which will be released on the 30th of June, 2021.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
B426_firmware | Bosch | 03.01.0004 (including) | 03.01.0004 (including) |
B426_firmware | Bosch | 03.02.002 (including) | 03.02.002 (including) |
B426_firmware | Bosch | 03.03.0009 (including) | 03.03.0009 (including) |
B426_firmware | Bosch | 03.05.0003 (including) | 03.05.0003 (including) |