← Back

CVE-2023-1750

nvd nist
Published: Apr 4, 2023Modified: Nov 21, 2024

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Exploitability: 2.8 / Impact: 4.2
Source: NVD

Description

The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a valid NexxHome deviceId could retrieve device history, set device settings, and retrieve device information.

Affected (4)

4 products
Nxal 100 Firmware
Nxg 100b Firmware
Nxpg 100w Firmware
Nxg 200 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to nxal100v-p1-9-1
Running on/withPlatform Versions
Getnexx
Nxal 100
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to nxg100bv-p3-4-1
Running on/withPlatform Versions
Getnexx
Nxg 100b
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to nxpg100cv4-0-0
Running on/withPlatform Versions
Getnexx
Nxpg 100w
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to nxg200v-p3-4-1
Running on/withPlatform Versions
Getnexx
Nxg 200
All versions

References (2)

Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.