Lucene search

K
cveBoschCVE-2023-48249
HistoryJan 10, 2024 - 11:15 a.m.

CVE-2023-48249

2024-01-1011:15:10
CWE-22
bosch
web.nvd.nist.gov
8
vulnerability
authenticated
remote attacker
arbitrary folders
system
application os user
http request
session cookies
nvd

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

28.0%

The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.

By abusing this vulnerability, it is possible to steal session cookies of other active users.

Affected configurations

Nvd
Node
boschnexo-osRange10001500-sp2
AND
boschnexo_cordless_nutrunner_nxa011s-36v-b_\(0608842012\)Match-
OR
boschnexo_cordless_nutrunner_nxa011s-36v_\(0608842011\)Match-
OR
boschnexo_cordless_nutrunner_nxa015s-36v-b_\(0608842006\)Match-
OR
boschnexo_cordless_nutrunner_nxa015s-36v_\(0608842001\)Match-
OR
boschnexo_cordless_nutrunner_nxa030s-36v-b_\(0608842007\)Match-
OR
boschnexo_cordless_nutrunner_nxa030s-36v_\(0608842002\)Match-
OR
boschnexo_cordless_nutrunner_nxa050s-36v-b_\(0608842008\)Match-
OR
boschnexo_cordless_nutrunner_nxa050s-36v_\(0608842003\)Match-
OR
boschnexo_cordless_nutrunner_nxa065s-36v-b_\(0608842014\)Match-
OR
boschnexo_cordless_nutrunner_nxa065s-36v_\(0608842013\)Match-
OR
boschnexo_cordless_nutrunner_nxp012qd-36v-b_\(0608842010\)Match-
OR
boschnexo_cordless_nutrunner_nxp012qd-36v_\(0608842005\)Match-
OR
boschnexo_cordless_nutrunner_nxv012t-36v-b_\(0608842016\)Match-
OR
boschnexo_cordless_nutrunner_nxv012t-36v_\(0608842015\)Match-
OR
boschnexo_special_cordless_nutrunner_\(0608pe2272\)Match-
OR
boschnexo_special_cordless_nutrunner_\(0608pe2301\)Match-
OR
boschnexo_special_cordless_nutrunner_\(0608pe2514\)Match-
OR
boschnexo_special_cordless_nutrunner_\(0608pe2515\)Match-
OR
boschnexo_special_cordless_nutrunner_\(0608pe2666\)Match-
OR
boschnexo_special_cordless_nutrunner_\(0608pe2673\)Match-
VendorProductVersionCPE
boschnexo-os*cpe:2.3:o:bosch:nexo-os:*:*:*:*:*:*:*:*
boschnexo_cordless_nutrunner_nxa011s-36v-b_\(0608842012\)-cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa011s-36v-b_\(0608842012\):-:*:*:*:*:*:*:*
boschnexo_cordless_nutrunner_nxa011s-36v_\(0608842011\)-cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa011s-36v_\(0608842011\):-:*:*:*:*:*:*:*
boschnexo_cordless_nutrunner_nxa015s-36v-b_\(0608842006\)-cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa015s-36v-b_\(0608842006\):-:*:*:*:*:*:*:*
boschnexo_cordless_nutrunner_nxa015s-36v_\(0608842001\)-cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa015s-36v_\(0608842001\):-:*:*:*:*:*:*:*
boschnexo_cordless_nutrunner_nxa030s-36v-b_\(0608842007\)-cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa030s-36v-b_\(0608842007\):-:*:*:*:*:*:*:*
boschnexo_cordless_nutrunner_nxa030s-36v_\(0608842002\)-cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa030s-36v_\(0608842002\):-:*:*:*:*:*:*:*
boschnexo_cordless_nutrunner_nxa050s-36v-b_\(0608842008\)-cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa050s-36v-b_\(0608842008\):-:*:*:*:*:*:*:*
boschnexo_cordless_nutrunner_nxa050s-36v_\(0608842003\)-cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa050s-36v_\(0608842003\):-:*:*:*:*:*:*:*
boschnexo_cordless_nutrunner_nxa065s-36v-b_\(0608842014\)-cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa065s-36v-b_\(0608842014\):-:*:*:*:*:*:*:*
Rows per page:
1-10 of 211

CNA Affected

[
  {
    "vendor": "Rexroth",
    "product": "Nexo cordless nutrunner NXA015S-36V (0608842001)",
    "versions": [
      {
        "version": "NEXO-OS V1000-Release",
        "status": "affected",
        "versionType": "custom",
        "lessThanOrEqual": "NEXO-OS V1500-SP2"
      }
    ]
  },
  {
    "vendor": "Rexroth",
    "product": "Nexo cordless nutrunner NXA030S-36V (0608842002)",
    "versions": [
      {
        "version": "NEXO-OS V1000-Release",
        "status": "affected",
        "versionType": "custom",
        "lessThanOrEqual": "NEXO-OS V1500-SP2"
      }
    ]
  },
  {
    "vendor": "Rexroth",
    "product": "Nexo cordless nutrunner NXA050S-36V (0608842003)",
    "versions": [
      {
        "version": "NEXO-OS V1000-Release",
        "status": "affected",
        "versionType": "custom",
        "lessThanOrEqual": "NEXO-OS V1500-SP2"
      }
    ]
  },
  {
    "vendor": "Rexroth",
    "product": "Nexo cordless nutrunner NXP012QD-36V (0608842005)",
    "versions": [
      {
        "version": "NEXO-OS V1000-Release",
        "status": "affected",
        "versionType": "custom",
        "lessThanOrEqual": "NEXO-OS V1500-SP2"
      }
    ]
  },
  {
    "vendor": "Rexroth",
    "product": "Nexo cordless nutrunner NXA015S-36V-B (0608842006)",
    "versions": [
      {
        "version": "NEXO-OS V1000-Release",
        "status": "affected",
        "versionType": "custom",
        "lessThanOrEqual": "NEXO-OS V1500-SP2"
      }
    ]
  },
  {
    "vendor": "Rexroth",
    "product": "Nexo cordless nutrunner NXA030S-36V-B (0608842007)",
    "versions": [
      {
        "version": "NEXO-OS V1000-Release",
        "status": "affected",
        "versionType": "custom",
        "lessThanOrEqual": "NEXO-OS V1500-SP2"
      }
    ]
  },
  {
    "vendor": "Rexroth",
    "product": "Nexo cordless nutrunner NXA050S-36V-B (0608842008)",
    "versions": [
      {
        "version": "NEXO-OS V1000-Release",
        "status": "affected",
        "versionType": "custom",
        "lessThanOrEqual": "NEXO-OS V1500-SP2"
      }
    ]
  },
  {
    "vendor": "Rexroth",
    "product": "Nexo cordless nutrunner NXP012QD-36V-B (0608842010)",
    "versions": [
      {
        "version": "NEXO-OS V1000-Release",
        "status": "affected",
        "versionType": "custom",
        "lessThanOrEqual": "NEXO-OS V1500-SP2"
      }
    ]
  },
  {
    "vendor": "Rexroth",
    "product": "Nexo cordless nutrunner NXA011S-36V (0608842011)",
    "versions": [
      {
        "version": "NEXO-OS V1000-Release",
        "status": "affected",
        "versionType": "custom",
        "lessThanOrEqual": "NEXO-OS V1500-SP2"
      }
    ]
  },
  {
    "vendor": "Rexroth",
    "product": "Nexo cordless nutrunner NXA011S-36V-B (0608842012)",
    "versions": [
      {
        "version": "NEXO-OS V1000-Release",
        "status": "affected",
        "versionType": "custom",
        "lessThanOrEqual": "NEXO-OS V1500-SP2"
      }
    ]
  },
  {
    "vendor": "Rexroth",
    "product": "Nexo cordless nutrunner NXA065S-36V (0608842013)",
    "versions": [
      {
        "version": "NEXO-OS V1000-Release",
        "status": "affected",
        "versionType": "custom",
        "lessThanOrEqual": "NEXO-OS V1500-SP2"
      }
    ]
  },
  {
    "vendor": "Rexroth",
    "product": "Nexo cordless nutrunner NXA065S-36V-B (0608842014)",
    "versions": [
      {
        "version": "NEXO-OS V1000-Release",
        "status": "affected",
        "versionType": "custom",
        "lessThanOrEqual": "NEXO-OS V1500-SP2"
      }
    ]
  },
  {
    "vendor": "Rexroth",
    "product": "Nexo cordless nutrunner NXV012T-36V (0608842015)",
    "versions": [
      {
        "version": "NEXO-OS V1000-Release",
        "status": "affected",
        "versionType": "custom",
        "lessThanOrEqual": "NEXO-OS V1500-SP2"
      }
    ]
  },
  {
    "vendor": "Rexroth",
    "product": "Nexo cordless nutrunner NXV012T-36V-B (0608842016)",
    "versions": [
      {
        "version": "NEXO-OS V1000-Release",
        "status": "affected",
        "versionType": "custom",
        "lessThanOrEqual": "NEXO-OS V1500-SP2"
      }
    ]
  },
  {
    "vendor": "Rexroth",
    "product": "Nexo special cordless nutrunner (0608PE2272)",
    "versions": [
      {
        "version": "NEXO-OS V1000-Release",
        "status": "affected",
        "versionType": "custom",
        "lessThanOrEqual": "NEXO-OS V1500-SP2"
      }
    ]
  },
  {
    "vendor": "Rexroth",
    "product": "Nexo special cordless nutrunner (0608PE2301)",
    "versions": [
      {
        "version": "NEXO-OS V1000-Release",
        "status": "affected",
        "versionType": "custom",
        "lessThanOrEqual": "NEXO-OS V1500-SP2"
      }
    ]
  },
  {
    "vendor": "Rexroth",
    "product": "Nexo special cordless nutrunner (0608PE2514)",
    "versions": [
      {
        "version": "NEXO-OS V1000-Release",
        "status": "affected",
        "versionType": "custom",
        "lessThanOrEqual": "NEXO-OS V1500-SP2"
      }
    ]
  },
  {
    "vendor": "Rexroth",
    "product": "Nexo special cordless nutrunner (0608PE2515)",
    "versions": [
      {
        "version": "NEXO-OS V1000-Release",
        "status": "affected",
        "versionType": "custom",
        "lessThanOrEqual": "NEXO-OS V1500-SP2"
      }
    ]
  },
  {
    "vendor": "Rexroth",
    "product": "Nexo special cordless nutrunner (0608PE2666)",
    "versions": [
      {
        "version": "NEXO-OS V1000-Release",
        "status": "affected",
        "versionType": "custom",
        "lessThanOrEqual": "NEXO-OS V1500-SP2"
      }
    ]
  },
  {
    "vendor": "Rexroth",
    "product": "Nexo special cordless nutrunner (0608PE2673)",
    "versions": [
      {
        "version": "NEXO-OS V1000-Release",
        "status": "affected",
        "versionType": "custom",
        "lessThanOrEqual": "NEXO-OS V1500-SP2"
      }
    ]
  }
]

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

28.0%

Related for CVE-2023-48249