CVE-2023-48242: Path Traversal
The vulnerability allows an authenticated remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48242?
CVE-2023-48242 is classified as a critical vulnerability due to its potential to allow remote file downloads with root access.
How do I fix CVE-2023-48242?
To fix CVE-2023-48242, apply the latest security patches provided by Bosch for affected Bosch Nexo OS versions.
Who is affected by CVE-2023-48242?
CVE-2023-48242 affects authenticated users of Bosch Nexo OS versions ranging from 1000 to 1500-sp2.
What can an attacker do with CVE-2023-48242?
An attacker exploiting CVE-2023-48242 can download arbitrary files from the system with root privileges.
Is there a workaround for CVE-2023-48242?
Currently, the most effective workaround for CVE-2023-48242 is to restrict access to the application until a patch is applied.