// For flags

CVE-2023-48253

 

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication database via a crafted HTTP request. By abusing this vulnerability it is possible to exfiltrate other users’ password hashes or update them with arbitrary values and access their accounts.

La vulnerabilidad permite a un atacante autenticado remoto leer o actualizar contenido arbitrario de la base de datos de autenticación mediante una solicitud HTTP manipulada. Al abusar de esta vulnerabilidad, es posible filtrar los hashes de contraseñas de otros usuarios o actualizarlos con valores arbitrarios y acceder a sus cuentas.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
None
Automatable
Yes
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2023-11-13 CVE Reserved
  • 2024-01-10 CVE Published
  • 2025-05-31 EPSS Updated
  • 2025-06-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Bosch
Search vendor "Bosch"
Nexo-os
Search vendor "Bosch" for product "Nexo-os"
>= 1000 <= 1500-sp2
Search vendor "Bosch" for product "Nexo-os" and version " >= 1000 <= 1500-sp2"
-
Affected
in Bosch
Search vendor "Bosch"
Nexo Cordless Nutrunner Nxa011s-36v-b \(0608842012\)
Search vendor "Bosch" for product "Nexo Cordless Nutrunner Nxa011s-36v-b \(0608842012\)"
--
Safe
Bosch
Search vendor "Bosch"
Nexo-os
Search vendor "Bosch" for product "Nexo-os"
>= 1000 <= 1500-sp2
Search vendor "Bosch" for product "Nexo-os" and version " >= 1000 <= 1500-sp2"
-
Affected
in Bosch
Search vendor "Bosch"
Nexo Cordless Nutrunner Nxa011s-36v \(0608842011\)
Search vendor "Bosch" for product "Nexo Cordless Nutrunner Nxa011s-36v \(0608842011\)"
--
Safe
Bosch
Search vendor "Bosch"
Nexo-os
Search vendor "Bosch" for product "Nexo-os"
>= 1000 <= 1500-sp2
Search vendor "Bosch" for product "Nexo-os" and version " >= 1000 <= 1500-sp2"
-
Affected
in Bosch
Search vendor "Bosch"
Nexo Cordless Nutrunner Nxa015s-36v-b \(0608842006\)
Search vendor "Bosch" for product "Nexo Cordless Nutrunner Nxa015s-36v-b \(0608842006\)"
--
Safe
Bosch
Search vendor "Bosch"
Nexo-os
Search vendor "Bosch" for product "Nexo-os"
>= 1000 <= 1500-sp2
Search vendor "Bosch" for product "Nexo-os" and version " >= 1000 <= 1500-sp2"
-
Affected
in Bosch
Search vendor "Bosch"
Nexo Cordless Nutrunner Nxa015s-36v \(0608842001\)
Search vendor "Bosch" for product "Nexo Cordless Nutrunner Nxa015s-36v \(0608842001\)"
--
Safe
Bosch
Search vendor "Bosch"
Nexo-os
Search vendor "Bosch" for product "Nexo-os"
>= 1000 <= 1500-sp2
Search vendor "Bosch" for product "Nexo-os" and version " >= 1000 <= 1500-sp2"
-
Affected
in Bosch
Search vendor "Bosch"
Nexo Cordless Nutrunner Nxa030s-36v-b \(0608842007\)
Search vendor "Bosch" for product "Nexo Cordless Nutrunner Nxa030s-36v-b \(0608842007\)"
--
Safe
Bosch
Search vendor "Bosch"
Nexo-os
Search vendor "Bosch" for product "Nexo-os"
>= 1000 <= 1500-sp2
Search vendor "Bosch" for product "Nexo-os" and version " >= 1000 <= 1500-sp2"
-
Affected
in Bosch
Search vendor "Bosch"
Nexo Cordless Nutrunner Nxa030s-36v \(0608842002\)
Search vendor "Bosch" for product "Nexo Cordless Nutrunner Nxa030s-36v \(0608842002\)"
--
Safe
Bosch
Search vendor "Bosch"
Nexo-os
Search vendor "Bosch" for product "Nexo-os"
>= 1000 <= 1500-sp2
Search vendor "Bosch" for product "Nexo-os" and version " >= 1000 <= 1500-sp2"
-
Affected
in Bosch
Search vendor "Bosch"
Nexo Cordless Nutrunner Nxa050s-36v-b \(0608842008\)
Search vendor "Bosch" for product "Nexo Cordless Nutrunner Nxa050s-36v-b \(0608842008\)"
--
Safe
Bosch
Search vendor "Bosch"
Nexo-os
Search vendor "Bosch" for product "Nexo-os"
>= 1000 <= 1500-sp2
Search vendor "Bosch" for product "Nexo-os" and version " >= 1000 <= 1500-sp2"
-
Affected
in Bosch
Search vendor "Bosch"
Nexo Cordless Nutrunner Nxa050s-36v \(0608842003\)
Search vendor "Bosch" for product "Nexo Cordless Nutrunner Nxa050s-36v \(0608842003\)"
--
Safe
Bosch
Search vendor "Bosch"
Nexo-os
Search vendor "Bosch" for product "Nexo-os"
>= 1000 <= 1500-sp2
Search vendor "Bosch" for product "Nexo-os" and version " >= 1000 <= 1500-sp2"
-
Affected
in Bosch
Search vendor "Bosch"
Nexo Cordless Nutrunner Nxa065s-36v-b \(0608842014\)
Search vendor "Bosch" for product "Nexo Cordless Nutrunner Nxa065s-36v-b \(0608842014\)"
--
Safe
Bosch
Search vendor "Bosch"
Nexo-os
Search vendor "Bosch" for product "Nexo-os"
>= 1000 <= 1500-sp2
Search vendor "Bosch" for product "Nexo-os" and version " >= 1000 <= 1500-sp2"
-
Affected
in Bosch
Search vendor "Bosch"
Nexo Cordless Nutrunner Nxa065s-36v \(0608842013\)
Search vendor "Bosch" for product "Nexo Cordless Nutrunner Nxa065s-36v \(0608842013\)"
--
Safe
Bosch
Search vendor "Bosch"
Nexo-os
Search vendor "Bosch" for product "Nexo-os"
>= 1000 <= 1500-sp2
Search vendor "Bosch" for product "Nexo-os" and version " >= 1000 <= 1500-sp2"
-
Affected
in Bosch
Search vendor "Bosch"
Nexo Cordless Nutrunner Nxp012qd-36v-b \(0608842010\)
Search vendor "Bosch" for product "Nexo Cordless Nutrunner Nxp012qd-36v-b \(0608842010\)"
--
Safe
Bosch
Search vendor "Bosch"
Nexo-os
Search vendor "Bosch" for product "Nexo-os"
>= 1000 <= 1500-sp2
Search vendor "Bosch" for product "Nexo-os" and version " >= 1000 <= 1500-sp2"
-
Affected
in Bosch
Search vendor "Bosch"
Nexo Cordless Nutrunner Nxp012qd-36v \(0608842005\)
Search vendor "Bosch" for product "Nexo Cordless Nutrunner Nxp012qd-36v \(0608842005\)"
--
Safe
Bosch
Search vendor "Bosch"
Nexo-os
Search vendor "Bosch" for product "Nexo-os"
>= 1000 <= 1500-sp2
Search vendor "Bosch" for product "Nexo-os" and version " >= 1000 <= 1500-sp2"
-
Affected
in Bosch
Search vendor "Bosch"
Nexo Cordless Nutrunner Nxv012t-36v-b \(0608842016\)
Search vendor "Bosch" for product "Nexo Cordless Nutrunner Nxv012t-36v-b \(0608842016\)"
--
Safe
Bosch
Search vendor "Bosch"
Nexo-os
Search vendor "Bosch" for product "Nexo-os"
>= 1000 <= 1500-sp2
Search vendor "Bosch" for product "Nexo-os" and version " >= 1000 <= 1500-sp2"
-
Affected
in Bosch
Search vendor "Bosch"
Nexo Cordless Nutrunner Nxv012t-36v \(0608842015\)
Search vendor "Bosch" for product "Nexo Cordless Nutrunner Nxv012t-36v \(0608842015\)"
--
Safe
Bosch
Search vendor "Bosch"
Nexo-os
Search vendor "Bosch" for product "Nexo-os"
>= 1000 <= 1500-sp2
Search vendor "Bosch" for product "Nexo-os" and version " >= 1000 <= 1500-sp2"
-
Affected
in Bosch
Search vendor "Bosch"
Nexo Special Cordless Nutrunner \(0608pe2272\)
Search vendor "Bosch" for product "Nexo Special Cordless Nutrunner \(0608pe2272\)"
--
Safe
Bosch
Search vendor "Bosch"
Nexo-os
Search vendor "Bosch" for product "Nexo-os"
>= 1000 <= 1500-sp2
Search vendor "Bosch" for product "Nexo-os" and version " >= 1000 <= 1500-sp2"
-
Affected
in Bosch
Search vendor "Bosch"
Nexo Special Cordless Nutrunner \(0608pe2301\)
Search vendor "Bosch" for product "Nexo Special Cordless Nutrunner \(0608pe2301\)"
--
Safe
Bosch
Search vendor "Bosch"
Nexo-os
Search vendor "Bosch" for product "Nexo-os"
>= 1000 <= 1500-sp2
Search vendor "Bosch" for product "Nexo-os" and version " >= 1000 <= 1500-sp2"
-
Affected
in Bosch
Search vendor "Bosch"
Nexo Special Cordless Nutrunner \(0608pe2514\)
Search vendor "Bosch" for product "Nexo Special Cordless Nutrunner \(0608pe2514\)"
--
Safe
Bosch
Search vendor "Bosch"
Nexo-os
Search vendor "Bosch" for product "Nexo-os"
>= 1000 <= 1500-sp2
Search vendor "Bosch" for product "Nexo-os" and version " >= 1000 <= 1500-sp2"
-
Affected
in Bosch
Search vendor "Bosch"
Nexo Special Cordless Nutrunner \(0608pe2515\)
Search vendor "Bosch" for product "Nexo Special Cordless Nutrunner \(0608pe2515\)"
--
Safe
Bosch
Search vendor "Bosch"
Nexo-os
Search vendor "Bosch" for product "Nexo-os"
>= 1000 <= 1500-sp2
Search vendor "Bosch" for product "Nexo-os" and version " >= 1000 <= 1500-sp2"
-
Affected
in Bosch
Search vendor "Bosch"
Nexo Special Cordless Nutrunner \(0608pe2666\)
Search vendor "Bosch" for product "Nexo Special Cordless Nutrunner \(0608pe2666\)"
--
Safe
Bosch
Search vendor "Bosch"
Nexo-os
Search vendor "Bosch" for product "Nexo-os"
>= 1000 <= 1500-sp2
Search vendor "Bosch" for product "Nexo-os" and version " >= 1000 <= 1500-sp2"
-
Affected
in Bosch
Search vendor "Bosch"
Nexo Special Cordless Nutrunner \(0608pe2673\)
Search vendor "Bosch" for product "Nexo Special Cordless Nutrunner \(0608pe2673\)"
--
Safe