CVE-2023-48243: Path Traversal
The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is possible to obtain remote code execution (RCE) with root privileges on the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48243?
CVE-2023-48243 is considered a critical vulnerability due to its potential to allow remote code execution with root privileges.
How do I fix CVE-2023-48243?
To fix CVE-2023-48243, it is essential to update the affected Bosch Nexo OS to the latest patched version.
Who is affected by CVE-2023-48243?
CVE-2023-48243 affects all versions of Bosch Nexo OS from 1000 to 1500-sp2.
What can an attacker do with CVE-2023-48243?
An attacker exploiting CVE-2023-48243 can upload arbitrary files, leading to potential remote code execution.
What is the nature of the exploit for CVE-2023-48243?
The exploit for CVE-2023-48243 involves sending a crafted HTTP request to the vulnerable system.