First published: Wed Jan 10 2024(Updated: )
The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request.
Credit: psirt@bosch.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Bosch Nexo-os | >=1000<=1500-sp2 | |
Any of | ||
Bosch Nexo Cordless Nutrunner Nxa011s-36v-b (0608842012) | ||
Bosch Nexo Cordless Nutrunner Nxa011s-36v | ||
Bosch Nexo Cordless Nutrunner Nxa015s-36v-b | ||
Bosch Nexo Cordless Nutrunner Nxa015s-36v | ||
Bosch Nexo Cordless Nutrunner Nxa030s-36v-b (0608842007) | ||
Bosch Nexo Cordless Nutrunner Nxa030s-36v | ||
Bosch Nexo Cordless Nutrunner Nxa050s-36v-b | ||
Bosch Nexo Cordless Nutrunner Nxa050s-36v | ||
Bosch Nexo Cordless Nutrunner Nxa065s-36v-b | ||
Bosch Nexo Cordless Nutrunner Nxa065s-36v | ||
Bosch Nexo Cordless Nutrunner Nxp012qd-36v-b | ||
Bosch Nexo Cordless Nutrunner Nxp012qd-36v | ||
Bosch Nexo Cordless Nutrunner Nxv012t-36v-b | ||
Bosch Nexo Cordless Nutrunner Nxv012t-36v (0608842015) | ||
Bosch Nexo Special Cordless Nutrunner | ||
Bosch Nexo Special Cordless Nutrunner | ||
Bosch Nexo Special Cordless Nutrunner | ||
Bosch Nexo Special Cordless Nutrunner | ||
Bosch Nexo Special Cordless Nutrunner (0608pe2666) | ||
Bosch Nexo Special Cordless Nutrunner |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-48264 has been identified as allowing unauthenticated remote attackers to potentially cause a Denial-of-Service (DoS) attack and possibly achieve Remote Code Execution (RCE).
To mitigate CVE-2023-48264, ensure that your software is updated to a version later than 1500-sp2 and monitor for any unusual network activity.
CVE-2023-48264 affects Bosch Nexo OS versions from 1000 to 1500-sp2.
Yes, a patch for CVE-2023-48264 is available through Bosch's security advisories.
While CVE-2023-48264 primarily allows DoS attacks, it may also expose systems to Remote Code Execution, which could lead to a potential system takeover.