CVE-2023-48255 is a medium-severity cross-site scripting (XSS) vulnerability affecting Bosch products, allowing an unauthenticated remote attacker to inject and execute arbitrary client-side script code within a victim's session. The attack requires user interaction (UI:R) via a crafted URL or HTTP request, leading to potential compromise of confidentiality and integrity (C:L/I:L). Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1000, <= 1500-sp2CPE matchmatch criteria | cpe:2.3:o:bosch:nexo-os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple vulnerabilities in Nexo cordless nutrunner
Jan 8, 2024Multiple vulnerabilities in Nexo cordless nutrunner
Jan 8, 2024Multiple vulnerabilities in Nexo cordless nutrunner
Jan 8, 2024Multiple vulnerabilities in Nexo cordless nutrunner
Jan 8, 2024