CVE-2023-48243
HIGHDescription
The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is possible to obtain remote code execution (RCE) with root privileges on the device.
Is your site exposed to CVE-2023-48243?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| bosch | nexo-os |
| bosch | nexo_cordless_nutrunner_nxa011s-36v-b_\(0608842012\) |
| bosch | nexo_cordless_nutrunner_nxa011s-36v_\(0608842011\) |
| bosch | nexo_cordless_nutrunner_nxa015s-36v-b_\(0608842006\) |
| bosch | nexo_cordless_nutrunner_nxa015s-36v_\(0608842001\) |
| bosch | nexo_cordless_nutrunner_nxa030s-36v-b_\(0608842007\) |
| bosch | nexo_cordless_nutrunner_nxa030s-36v_\(0608842002\) |
| bosch | nexo_cordless_nutrunner_nxa050s-36v-b_\(0608842008\) |
| bosch | nexo_cordless_nutrunner_nxa050s-36v_\(0608842003\) |
| bosch | nexo_cordless_nutrunner_nxa065s-36v-b_\(0608842014\) |
| bosch | nexo_cordless_nutrunner_nxa065s-36v_\(0608842013\) |
| bosch | nexo_cordless_nutrunner_nxp012qd-36v-b_\(0608842010\) |
| bosch | nexo_cordless_nutrunner_nxp012qd-36v_\(0608842005\) |
| bosch | nexo_cordless_nutrunner_nxv012t-36v-b_\(0608842016\) |
| bosch | nexo_cordless_nutrunner_nxv012t-36v_\(0608842015\) |
| bosch | nexo_special_cordless_nutrunner_\(0608pe2272\) |
| bosch | nexo_special_cordless_nutrunner_\(0608pe2301\) |
| bosch | nexo_special_cordless_nutrunner_\(0608pe2514\) |
| bosch | nexo_special_cordless_nutrunner_\(0608pe2515\) |
| bosch | nexo_special_cordless_nutrunner_\(0608pe2666\) |
| bosch | nexo_special_cordless_nutrunner_\(0608pe2673\) |
References
Frequently Asked Questions
What is CVE-2023-48243? +
How severe is CVE-2023-48243? +
What products are affected by CVE-2023-48243? +
How do I check if I'm vulnerable to CVE-2023-48243? +
Related Vulnerabilities
Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior …
Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/packages/packages.toml content. Package keys read from build/packages/packages.toml …
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal …
Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-426 extracts sdist tarballs without path …
Kenik Camera management Panel is vulnerable to Path Traversal vulnerability. An unauthenticated attacker can send GET request with arbitrary file …
Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to …