← Back

CVE-2023-48249

nvd nist
Published: Jan 10, 2024Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is possible to steal session cookies of other active users.

Affected (1)

Products: Bosch: Nexo Os
1 product
Nexo Os
Configuration A
1 vulnerable · 20 platform
Vulnerable SoftwareAffected Versions
From 1000 to 1500-sp2
Running on/withPlatform Versions
Bosch
Nexo Cordless Nutrunner Nxa011s 36v B (0608842012)
All versions
Bosch
Nexo Cordless Nutrunner Nxa011s 36v (0608842011)
All versions
Bosch
Nexo Cordless Nutrunner Nxa015s 36v B (0608842006)
All versions
Bosch
Nexo Cordless Nutrunner Nxa015s 36v (0608842001)
All versions
Bosch
Nexo Cordless Nutrunner Nxa030s 36v B (0608842007)
All versions
Bosch
Nexo Cordless Nutrunner Nxa030s 36v (0608842002)
All versions
Bosch
Nexo Cordless Nutrunner Nxa050s 36v B (0608842008)
All versions
Bosch
Nexo Cordless Nutrunner Nxa050s 36v (0608842003)
All versions
Bosch
Nexo Cordless Nutrunner Nxa065s 36v B (0608842014)
All versions
Bosch
Nexo Cordless Nutrunner Nxa065s 36v (0608842013)
All versions
Bosch
Nexo Cordless Nutrunner Nxp012qd 36v B (0608842010)
All versions
Bosch
Nexo Cordless Nutrunner Nxp012qd 36v (0608842005)
All versions
Bosch
Nexo Cordless Nutrunner Nxv012t 36v B (0608842016)
All versions
Bosch
Nexo Cordless Nutrunner Nxv012t 36v (0608842015)
All versions
Bosch
Nexo Special Cordless Nutrunner (0608pe2272)
All versions
Bosch
Nexo Special Cordless Nutrunner (0608pe2301)
All versions
Bosch
Nexo Special Cordless Nutrunner (0608pe2514)
All versions
Bosch
Nexo Special Cordless Nutrunner (0608pe2515)
All versions
Bosch
Nexo Special Cordless Nutrunner (0608pe2666)
All versions
Bosch
Nexo Special Cordless Nutrunner (0608pe2673)
All versions

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.