CVE-2023-48253
10.01.2024, 13:15
The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication database via a crafted HTTP request. By abusing this vulnerability it is possible to exfiltrate other users password hashes or update them with arbitrary values and access their accounts.
Vendor | Product | Version |
---|---|---|
bosch | nexo-os | 1000 ≤ 𝑥 ≤ 1500-sp2 |
𝑥
= Vulnerable software versions