CVE-2023-48250: Critical severity bosch nexo-os vulnerability
Published Jan 10, 2024
·Updated
The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded accounts.
Affected Software
21 affected components
All of the following
Bosch Nexo-os>=1000<=1500-sp2
Any of the following
Bosch Nexo Cordless Nutrunner Nxa011s-36v-b \(0608842012\)
Bosch Nexo Cordless Nutrunner Nxa011s-36v \(0608842011\)
Bosch Nexo Cordless Nutrunner Nxa015s-36v-b \(0608842006\)
Bosch Nexo Cordless Nutrunner Nxa015s-36v \(0608842001\)
Bosch Nexo Cordless Nutrunner Nxa030s-36v-b \(0608842007\)
Bosch Nexo Cordless Nutrunner Nxa030s-36v \(0608842002\)
Bosch Nexo Cordless Nutrunner Nxa050s-36v-b \(0608842008\)
Bosch Nexo Cordless Nutrunner Nxa050s-36v \(0608842003\)
Bosch Nexo Cordless Nutrunner Nxa065s-36v-b \(0608842014\)
Bosch Nexo Cordless Nutrunner Nxa065s-36v \(0608842013\)
Bosch Nexo Cordless Nutrunner Nxp012qd-36v-b \(0608842010\)
Bosch Nexo Cordless Nutrunner Nxp012qd-36v \(0608842005\)
Bosch Nexo Cordless Nutrunner Nxv012t-36v-b \(0608842016\)
Bosch Nexo Cordless Nutrunner Nxv012t-36v \(0608842015\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2272\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2301\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2514\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2515\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2666\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2673\)
Event History
Jan 10, 2024
CVE Published
via MITRE·10:43 AM
Data Sourced
via MITRE·10:43 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2023-48250?
The severity of CVE-2023-48250 is critical, as it allows remote attackers to authenticate with high privileges.
2
How do I fix CVE-2023-48250?
To fix CVE-2023-48250, ensure you update to a patched version of Bosch Nexo OS beyond 1500-sp2.
3
What systems are affected by CVE-2023-48250?
CVE-2023-48250 affects Bosch Nexo OS versions from 1000 to 1500-sp2.
4
How can attackers exploit CVE-2023-48250?
Attackers can exploit CVE-2023-48250 by using hidden hard-coded accounts to gain unauthorized high-level access.
5
What are the potential consequences of CVE-2023-48250?
The potential consequences of CVE-2023-48250 include unauthorized access to sensitive data and critical system controls.