Nexo Os
Vendor:
First CVE: Jan 10, 2024 · Active for 2 years
25
Total CVEs
More Total CVEs than 96% of tracked products
25.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 72% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Nexo Os over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 10, 2024
2 years ago
Most Recent CVE
Jan 10, 2024
930 days ago
CVE Severity & Scoring
Nexo Os25 CVEs
32%
36%
32%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network25 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low25 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None19 (76.0%)
Unknown0 (0.0%)
Required6 (24.0%)
Privileges Required
Low8 (32.0%)
High0 (0.0%)
None17 (68.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48266CRITICAL The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network reque | Jan 10, 2024 | 9.8 | 30 | NO | NO |
CVE-2023-48250CRITICAL The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded accounts. | Jan 10, 2024 | 9.8 | 28 | NO | NO |
CVE-2023-48245CRITICAL The vulnerability allows an unauthenticated remote attacker to upload arbitrary files under the context of the application OS user (“root”) via a crafted HTTP request. | Jan 10, 2024 | 9.8 | 28 | NO | NO |
CVE-2023-48253HIGH The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication database via a crafted HTTP request.
By abusing this vulnerabili | Jan 10, 2024 | 8.8 | 27 | NO | NO |
CVE-2023-48265CRITICAL The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network reque | Jan 10, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-48264CRITICAL The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network reque | Jan 10, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-48263CRITICAL The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network reque | Jan 10, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-48262CRITICAL The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network reque | Jan 10, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-48257HIGH The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) with root privileges on the device. The vul | Jan 10, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-48252HIGH The vulnerability allows an authenticated remote attacker to perform actions exceeding their authorized access via crafted HTTP requests. | Jan 10, 2024 | 8.8 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (25 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (25 CVEs).
Media Mentions
Signals from CVEs in this product scope (25 CVEs).
Top CNAs Publishing CVEs For Nexo Os
Top CWEs
Versions
No cataloged versions.