CVE-2023-48243 is a critical vulnerability affecting Bosch products, allowing a remote attacker to upload arbitrary files to any system path with root privileges via a crafted HTTP request. This flaw can lead to remote code execution (RCE) with the highest system permissions. Rated with a CVSS score of 8.8 (High), it presents a significant risk due to its low attack complexity and severe impact on confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, the potential for root-level RCE necessitates immediate attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1000, <= 1500-sp2CPE matchmatch criteria | cpe:2.3:o:bosch:nexo-os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple vulnerabilities in Nexo cordless nutrunner
Jan 8, 2024Multiple vulnerabilities in Nexo cordless nutrunner
Jan 8, 2024Multiple vulnerabilities in Nexo cordless nutrunner
Jan 8, 2024Multiple vulnerabilities in Nexo cordless nutrunner
Jan 8, 2024