CVE-2023-48249: Path Traversal
The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is possible to steal session cookies of other active users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48249?
CVE-2023-48249 has a high severity due to its potential to expose sensitive session information.
How do I fix CVE-2023-48249?
To remediate CVE-2023-48249, update the affected Bosch Nexo OS to the latest patched version.
Who is affected by CVE-2023-48249?
CVE-2023-48249 affects users of Bosch Nexo OS versions between 1000 and 1500-sp2.
What type of attack is CVE-2023-48249 associated with?
CVE-2023-48249 is associated with authenticated remote attacks that can list arbitrary folders.
What information can be exposed due to CVE-2023-48249?
Exploitation of CVE-2023-48249 can lead to the exposure of session cookies from other active users.