CVE-2023-48246: Path Traversal
Published Jan 10, 2024
·Updated
The vulnerability allows a remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.
Affected Software
21 affected components
All of the following
Bosch Nexo-os>=1000<=1500-sp2
Any of the following
Bosch Nexo Cordless Nutrunner Nxa011s-36v-b \(0608842012\)
Bosch Nexo Cordless Nutrunner Nxa011s-36v \(0608842011\)
Bosch Nexo Cordless Nutrunner Nxa015s-36v-b \(0608842006\)
Bosch Nexo Cordless Nutrunner Nxa015s-36v \(0608842001\)
Bosch Nexo Cordless Nutrunner Nxa030s-36v-b \(0608842007\)
Bosch Nexo Cordless Nutrunner Nxa030s-36v \(0608842002\)
Bosch Nexo Cordless Nutrunner Nxa050s-36v-b \(0608842008\)
Bosch Nexo Cordless Nutrunner Nxa050s-36v \(0608842003\)
Bosch Nexo Cordless Nutrunner Nxa065s-36v-b \(0608842014\)
Bosch Nexo Cordless Nutrunner Nxa065s-36v \(0608842013\)
Bosch Nexo Cordless Nutrunner Nxp012qd-36v-b \(0608842010\)
Bosch Nexo Cordless Nutrunner Nxp012qd-36v \(0608842005\)
Bosch Nexo Cordless Nutrunner Nxv012t-36v-b \(0608842016\)
Bosch Nexo Cordless Nutrunner Nxv012t-36v \(0608842015\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2272\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2301\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2514\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2515\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2666\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2673\)
Event History
Jan 10, 2024
CVE Published
via MITRE·10:39 AM
Data Sourced
via MITRE·10:39 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2023-48246?
CVE-2023-48246 is considered a high severity vulnerability due to its ability to allow remote attackers to download arbitrary files.
2
How do I fix CVE-2023-48246?
To fix CVE-2023-48246, update the affected Bosch Nexo-OS software to the latest version that addresses this vulnerability.
3
Which versions of Bosch Nexo-OS are affected by CVE-2023-48246?
CVE-2023-48246 affects Bosch Nexo-OS versions from 1000 up to 1500-sp2.
4
What are the risks associated with CVE-2023-48246?
The risks include unauthorized access to sensitive files on the system, potentially compromising data and application integrity.
5
Is there a proof of concept for CVE-2023-48246?
The details regarding a proof of concept for CVE-2023-48246 are not publicly disclosed to avoid exploitation.