CVE-2023-48245: Critical severity bosch nexo-os vulnerability
The vulnerability allows an unauthenticated remote attacker to upload arbitrary files under the context of the application OS user (“root”) via a crafted HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48245?
CVE-2023-48245 is classified as a critical vulnerability due to its ability to allow unauthenticated remote file uploads as the root user.
How do I fix CVE-2023-48245?
To mitigate CVE-2023-48245, apply the latest security patch provided by Bosch for the Nexo OS before version 1500-sp2.
What systems are affected by CVE-2023-48245?
CVE-2023-48245 affects Bosch Nexo OS versions between 1000 and 1500-sp2, allowing arbitrary file uploads.
Who can exploit CVE-2023-48245?
CVE-2023-48245 can be exploited by any unauthenticated remote attacker capable of sending a crafted HTTP request.
What kind of files can be uploaded through CVE-2023-48245?
CVE-2023-48245 allows attackers to upload arbitrary files, posing serious risks to system integrity and security.