CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
Percentile
27.8%
The vulnerability allows an unauthenticated remote attacker to send malicious network requests containing arbitrary client-side script code and obtain its execution inside a victim’s session via a crafted URL, HTTP request, or simply by waiting for the victim to view the poisoned log.
Vendor | Product | Version | CPE |
---|---|---|---|
bosch | nexo-os | * | cpe:2.3:o:bosch:nexo-os:*:*:*:*:*:*:*:* |
bosch | nexo_cordless_nutrunner_nxa011s-36v-b_\(0608842012\) | - | cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa011s-36v-b_\(0608842012\):-:*:*:*:*:*:*:* |
bosch | nexo_cordless_nutrunner_nxa011s-36v_\(0608842011\) | - | cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa011s-36v_\(0608842011\):-:*:*:*:*:*:*:* |
bosch | nexo_cordless_nutrunner_nxa015s-36v-b_\(0608842006\) | - | cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa015s-36v-b_\(0608842006\):-:*:*:*:*:*:*:* |
bosch | nexo_cordless_nutrunner_nxa015s-36v_\(0608842001\) | - | cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa015s-36v_\(0608842001\):-:*:*:*:*:*:*:* |
bosch | nexo_cordless_nutrunner_nxa030s-36v-b_\(0608842007\) | - | cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa030s-36v-b_\(0608842007\):-:*:*:*:*:*:*:* |
bosch | nexo_cordless_nutrunner_nxa030s-36v_\(0608842002\) | - | cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa030s-36v_\(0608842002\):-:*:*:*:*:*:*:* |
bosch | nexo_cordless_nutrunner_nxa050s-36v-b_\(0608842008\) | - | cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa050s-36v-b_\(0608842008\):-:*:*:*:*:*:*:* |
bosch | nexo_cordless_nutrunner_nxa050s-36v_\(0608842003\) | - | cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa050s-36v_\(0608842003\):-:*:*:*:*:*:*:* |
bosch | nexo_cordless_nutrunner_nxa065s-36v-b_\(0608842014\) | - | cpe:2.3:h:bosch:nexo_cordless_nutrunner_nxa065s-36v-b_\(0608842014\):-:*:*:*:*:*:*:* |