CVE-2023-48253: SQL Injection
The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication database via a crafted HTTP request. By abusing this vulnerability it is possible to exfiltrate other users’ password hashes or update them with arbitrary values and access their accounts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48253?
The severity of CVE-2023-48253 is considered critical due to the potential for remote authenticated attackers to exploit the vulnerability to read or update sensitive authentication database content.
How do I fix CVE-2023-48253?
To fix CVE-2023-48253, apply the latest security patches provided by Bosch for the affected Nexo operating system.
What types of attacks can be executed using CVE-2023-48253?
CVE-2023-48253 can enable attackers to exfiltrate other users' password hashes or update them with arbitrary values, compromising user accounts.
Is my device vulnerable to CVE-2023-48253?
Devices running Bosch Nexo OS versions between 1000 and 1500-sp2 are vulnerable to CVE-2023-48253, while certain models of the Bosch Nexo Cordless Nutrunner are not affected.
What should I do if I believe I've been affected by CVE-2023-48253?
If you suspect that you have been affected by CVE-2023-48253, immediately review your account access logs, change your passwords, and apply the recommended security updates.