CVE-2023-48257: High severity bosch nexo-os vulnerability
The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) with root privileges on the device. The vulnerability can be exploited directly by authenticated users, via crafted HTTP requests, or indirectly by unauthenticated users, by accessing already-exported backup packages, or crafting an import package and inducing an authenticated victim into sending the HTTP upload request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48257?
CVE-2023-48257 is considered a critical vulnerability due to its potential for remote code execution with root privileges.
How can I fix CVE-2023-48257?
To mitigate CVE-2023-48257, it is recommended to apply the latest patches provided by Bosch for the affected Nexo OS.
Who can exploit CVE-2023-48257?
Both authenticated users and unauthenticated users can exploit CVE-2023-48257 through specially crafted HTTP requests.
What are the consequences of exploiting CVE-2023-48257?
Exploitation of CVE-2023-48257 can lead to unauthorized access to sensitive data and the potential for remote code execution.
Which software is affected by CVE-2023-48257?
CVE-2023-48257 affects Bosch Nexo OS versions between 1000 and 1500-sp2.