Lucene search

K
nvd[email protected]NVD:CVE-2023-48242
HistoryJan 10, 2024 - 11:15 a.m.

CVE-2023-48242

2024-01-1011:15:08
CWE-22
web.nvd.nist.gov
5
vulnerability
authenticated
remote attacker
download
arbitrary files
crafted http request
application os user
root
system paths

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

28.0%

The vulnerability allows an authenticated remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.

Affected configurations

Nvd
Node
boschnexo-osRange10001500-sp2
AND
boschnexo_cordless_nutrunner_nxa011s-36v-b_\(0608842012\)Match-
OR
boschnexo_cordless_nutrunner_nxa011s-36v_\(0608842011\)Match-
OR
boschnexo_cordless_nutrunner_nxa015s-36v-b_\(0608842006\)Match-
OR
boschnexo_cordless_nutrunner_nxa015s-36v_\(0608842001\)Match-
OR
boschnexo_cordless_nutrunner_nxa030s-36v-b_\(0608842007\)Match-
OR
boschnexo_cordless_nutrunner_nxa030s-36v_\(0608842002\)Match-
OR
boschnexo_cordless_nutrunner_nxa050s-36v-b_\(0608842008\)Match-
OR
boschnexo_cordless_nutrunner_nxa050s-36v_\(0608842003\)Match-
OR
boschnexo_cordless_nutrunner_nxa065s-36v-b_\(0608842014\)Match-
OR
boschnexo_cordless_nutrunner_nxa065s-36v_\(0608842013\)Match-
OR
boschnexo_cordless_nutrunner_nxp012qd-36v-b_\(0608842010\)Match-
OR
boschnexo_cordless_nutrunner_nxp012qd-36v_\(0608842005\)Match-
OR
boschnexo_cordless_nutrunner_nxv012t-36v-b_\(0608842016\)Match-
OR
boschnexo_cordless_nutrunner_nxv012t-36v_\(0608842015\)Match-
OR
boschnexo_special_cordless_nutrunner_\(0608pe2272\)Match-
OR
boschnexo_special_cordless_nutrunner_\(0608pe2301\)Match-
OR
boschnexo_special_cordless_nutrunner_\(0608pe2514\)Match-
OR
boschnexo_special_cordless_nutrunner_\(0608pe2515\)Match-
OR
boschnexo_special_cordless_nutrunner_\(0608pe2666\)Match-
OR
boschnexo_special_cordless_nutrunner_\(0608pe2673\)Match-
VendorProductVersionCPE
boschnexo-os*cpe:2.3:o:bosch:nexo-os:*:*:*:*:*:*:*:*
boschnexo_cordless_nutrunner_nxa011s-36v-b_\(0608842012\)-cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa011s-36v-b_\(0608842012\):-:*:*:*:*:*:*:*
boschnexo_cordless_nutrunner_nxa011s-36v_\(0608842011\)-cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa011s-36v_\(0608842011\):-:*:*:*:*:*:*:*
boschnexo_cordless_nutrunner_nxa015s-36v-b_\(0608842006\)-cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa015s-36v-b_\(0608842006\):-:*:*:*:*:*:*:*
boschnexo_cordless_nutrunner_nxa015s-36v_\(0608842001\)-cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa015s-36v_\(0608842001\):-:*:*:*:*:*:*:*
boschnexo_cordless_nutrunner_nxa030s-36v-b_\(0608842007\)-cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa030s-36v-b_\(0608842007\):-:*:*:*:*:*:*:*
boschnexo_cordless_nutrunner_nxa030s-36v_\(0608842002\)-cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa030s-36v_\(0608842002\):-:*:*:*:*:*:*:*
boschnexo_cordless_nutrunner_nxa050s-36v-b_\(0608842008\)-cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa050s-36v-b_\(0608842008\):-:*:*:*:*:*:*:*
boschnexo_cordless_nutrunner_nxa050s-36v_\(0608842003\)-cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa050s-36v_\(0608842003\):-:*:*:*:*:*:*:*
boschnexo_cordless_nutrunner_nxa065s-36v-b_\(0608842014\)-cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa065s-36v-b_\(0608842014\):-:*:*:*:*:*:*:*
Rows per page:
1-10 of 211

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

28.0%

Related for NVD:CVE-2023-48242