CVE-2023-48258: CSRF
Published Jan 10, 2024
·Updated
The vulnerability allows a remote attacker to delete arbitrary files on the file system via a crafted URL or HTTP request through a victim’s session.
Affected Software
21 affected components
All of the following
Bosch Nexo-os>=1000<=1500-sp2
Any of the following
Bosch Nexo Cordless Nutrunner Nxa011s-36v-b \(0608842012\)
Bosch Nexo Cordless Nutrunner Nxa011s-36v \(0608842011\)
Bosch Nexo Cordless Nutrunner Nxa015s-36v-b \(0608842006\)
Bosch Nexo Cordless Nutrunner Nxa015s-36v \(0608842001\)
Bosch Nexo Cordless Nutrunner Nxa030s-36v-b \(0608842007\)
Bosch Nexo Cordless Nutrunner Nxa030s-36v \(0608842002\)
Bosch Nexo Cordless Nutrunner Nxa050s-36v-b \(0608842008\)
Bosch Nexo Cordless Nutrunner Nxa050s-36v \(0608842003\)
Bosch Nexo Cordless Nutrunner Nxa065s-36v-b \(0608842014\)
Bosch Nexo Cordless Nutrunner Nxa065s-36v \(0608842013\)
Bosch Nexo Cordless Nutrunner Nxp012qd-36v-b \(0608842010\)
Bosch Nexo Cordless Nutrunner Nxp012qd-36v \(0608842005\)
Bosch Nexo Cordless Nutrunner Nxv012t-36v-b \(0608842016\)
Bosch Nexo Cordless Nutrunner Nxv012t-36v \(0608842015\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2272\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2301\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2514\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2515\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2666\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2673\)
Event History
Jan 10, 2024
CVE Published
via MITRE·01:05 PM
Data Sourced
via MITRE·01:05 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2023-48258?
CVE-2023-48258 has a high severity rating as it allows remote attackers to delete arbitrary files from the file system.
2
What types of systems are affected by CVE-2023-48258?
CVE-2023-48258 affects Bosch Nexo OS versions from 1000 to 1500-SP2.
3
How do I fix CVE-2023-48258?
To fix CVE-2023-48258, update your Bosch Nexo OS to a version above 1500-SP2 or apply any available security patches.
4
What can attackers do with CVE-2023-48258?
Attackers exploiting CVE-2023-48258 can manipulate a victim’s session to delete arbitrary files, leading to potential data loss.
5
Is there a workaround for CVE-2023-48258?
Currently, there are no known workarounds for CVE-2023-48258 other than applying the latest software updates.