CVE-2023-48261: SQL Injection
Published Jan 10, 2024
·Updated
The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request.
Affected Software
21 affected components
All of the following
Bosch Nexo-os>=1000<=1500-sp2
Any of the following
Bosch Nexo Cordless Nutrunner Nxa011s-36v-b \(0608842012\)
Bosch Nexo Cordless Nutrunner Nxa011s-36v \(0608842011\)
Bosch Nexo Cordless Nutrunner Nxa015s-36v-b \(0608842006\)
Bosch Nexo Cordless Nutrunner Nxa015s-36v \(0608842001\)
Bosch Nexo Cordless Nutrunner Nxa030s-36v-b \(0608842007\)
Bosch Nexo Cordless Nutrunner Nxa030s-36v \(0608842002\)
Bosch Nexo Cordless Nutrunner Nxa050s-36v-b \(0608842008\)
Bosch Nexo Cordless Nutrunner Nxa050s-36v \(0608842003\)
Bosch Nexo Cordless Nutrunner Nxa065s-36v-b \(0608842014\)
Bosch Nexo Cordless Nutrunner Nxa065s-36v \(0608842013\)
Bosch Nexo Cordless Nutrunner Nxp012qd-36v-b \(0608842010\)
Bosch Nexo Cordless Nutrunner Nxp012qd-36v \(0608842005\)
Bosch Nexo Cordless Nutrunner Nxv012t-36v-b \(0608842016\)
Bosch Nexo Cordless Nutrunner Nxv012t-36v \(0608842015\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2272\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2301\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2514\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2515\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2666\)
Bosch Nexo Special Cordless Nutrunner \(0608pe2673\)
Event History
Jan 10, 2024
CVE Published
via MITRE·01:07 PM
Data Sourced
via MITRE·01:07 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2023-48261?
CVE-2023-48261 is rated as a critical vulnerability because it allows remote unauthenticated attackers to read arbitrary database content.
2
How do I fix CVE-2023-48261?
To mitigate CVE-2023-48261, you should update the affected Bosch Nexo OS to a version above 1500-sp2.
3
Who is affected by CVE-2023-48261?
CVE-2023-48261 affects users of Bosch Nexo OS versions ranging from 1000 to 1500-sp2.
4
What types of attacks can exploit CVE-2023-48261?
CVE-2023-48261 can be exploited through crafted HTTP requests that allow unauthorized content access from the database.
5
Is there a permanent patch available for CVE-2023-48261?
Yes, Bosch has released a patch for CVE-2023-48261 that resolves the vulnerability effectively in the new software version.