8.8

CVE-2023-48243

The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.
By abusing this vulnerability, it is possible to obtain remote code execution (RCE) with root privileges on the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BoschNexo-os Version >= 1000 <= 1500-sp2
   BoschNexo Cordless Nutrunner Nxa011s-36v-b (0608842012) Version-
   BoschNexo Cordless Nutrunner Nxa011s-36v (0608842011) Version-
   BoschNexo Cordless Nutrunner Nxa015s-36v-b (0608842006) Version-
   BoschNexo Cordless Nutrunner Nxa015s-36v (0608842001) Version-
   BoschNexo Cordless Nutrunner Nxa030s-36v-b (0608842007) Version-
   BoschNexo Cordless Nutrunner Nxa030s-36v (0608842002) Version-
   BoschNexo Cordless Nutrunner Nxa050s-36v-b (0608842008) Version-
   BoschNexo Cordless Nutrunner Nxa050s-36v (0608842003) Version-
   BoschNexo Cordless Nutrunner Nxa065s-36v-b (0608842014) Version-
   BoschNexo Cordless Nutrunner Nxa065s-36v (0608842013) Version-
   BoschNexo Cordless Nutrunner Nxp012qd-36v-b (0608842010) Version-
   BoschNexo Cordless Nutrunner Nxp012qd-36v (0608842005) Version-
   BoschNexo Cordless Nutrunner Nxv012t-36v-b (0608842016) Version-
   BoschNexo Cordless Nutrunner Nxv012t-36v (0608842015) Version-
   BoschNexo Special Cordless Nutrunner (0608pe2272) Version-
   BoschNexo Special Cordless Nutrunner (0608pe2301) Version-
   BoschNexo Special Cordless Nutrunner (0608pe2514) Version-
   BoschNexo Special Cordless Nutrunner (0608pe2515) Version-
   BoschNexo Special Cordless Nutrunner (0608pe2666) Version-
   BoschNexo Special Cordless Nutrunner (0608pe2673) Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.07% 0.834
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
psirt@bosch.com 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.