7.5

CVE-2023-1751

CVE-2023-1751

The listed versions of Nexx Smart Home devices use a WebSocket server that does not validate if the bearer token in the Authorization header belongs to the device attempting to associate. This could allow any authorized user to receive alarm information and signals meant for other devices which leak a deviceId.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GetnexxNxal-100 Firmware Version <= nxal100v-p1-9-1
   GetnexxNxal-100 Version-
GetnexxNxg-100b Firmware Version <= nxg100bv-p3-4-1
   GetnexxNxg-100b Version-
GetnexxNxpg-100w Firmware Version <= nxpg100cv4-0-0
   GetnexxNxpg-100w Version-
GetnexxNxg-200 Firmware Version <= nxg200v-p3-4-1
   GetnexxNxg-200 Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.59% 0.434
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
ics-cert@hq.dhs.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://www.cisa.gov/news-events/ics-advisories/icsa-23-094-01
Third Party Advisory
US Government Resource