First published: Wed Jan 10 2024(Updated: )
The vulnerability allows a remote attacker to delete arbitrary files on the file system via a crafted URL or HTTP request through a victim’s session.
Credit: psirt@bosch.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Bosch Nexo-os | >=1000<=1500-sp2 | |
Any of | ||
Bosch Nexo Cordless Nutrunner Nxa011s-36v-b (0608842012) | ||
Bosch Nexo Cordless Nutrunner Nxa011s-36v | ||
Bosch Nexo Cordless Nutrunner Nxa015s-36v-b | ||
Bosch Nexo Cordless Nutrunner Nxa015s-36v | ||
Bosch Nexo Cordless Nutrunner Nxa030s-36v-b (0608842007) | ||
Bosch Nexo Cordless Nutrunner Nxa030s-36v | ||
Bosch Nexo Cordless Nutrunner Nxa050s-36v-b | ||
Bosch Nexo Cordless Nutrunner Nxa050s-36v | ||
Bosch Nexo Cordless Nutrunner Nxa065s-36v-b | ||
Bosch Nexo Cordless Nutrunner Nxa065s-36v | ||
Bosch Nexo Cordless Nutrunner Nxp012qd-36v-b | ||
Bosch Nexo Cordless Nutrunner Nxp012qd-36v | ||
Bosch Nexo Cordless Nutrunner Nxv012t-36v-b | ||
Bosch Nexo Cordless Nutrunner Nxv012t-36v (0608842015) | ||
Bosch Nexo Special Cordless Nutrunner | ||
Bosch Nexo Special Cordless Nutrunner | ||
Bosch Nexo Special Cordless Nutrunner | ||
Bosch Nexo Special Cordless Nutrunner | ||
Bosch Nexo Special Cordless Nutrunner (0608pe2666) | ||
Bosch Nexo Special Cordless Nutrunner |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-48258 has a high severity rating as it allows remote attackers to delete arbitrary files from the file system.
CVE-2023-48258 affects Bosch Nexo OS versions from 1000 to 1500-SP2.
To fix CVE-2023-48258, update your Bosch Nexo OS to a version above 1500-SP2 or apply any available security patches.
Attackers exploiting CVE-2023-48258 can manipulate a victim’s session to delete arbitrary files, leading to potential data loss.
Currently, there are no known workarounds for CVE-2023-48258 other than applying the latest software updates.