The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request
Published Jan 10, 2024
8.8
HIGHCVSS 3.1
EPSS 1.09%
Description
The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is possible to obtain remote code execution (RCE) with root privileges on the device.
Affected products
-
Affected
- ≥ NEXO-OS V1000-Release, ≤ NEXO-OS V1500-SP2
-
Affected
- ≥ NEXO-OS V1000-Release, ≤ NEXO-OS V1500-SP2
-
Affected
- ≥ NEXO-OS V1000-Release, ≤ NEXO-OS V1500-SP2
-
Affected
- ≥ NEXO-OS V1000-Release, ≤ NEXO-OS V1500-SP2
-
Affected
- ≥ NEXO-OS V1000-Release, ≤ NEXO-OS V1500-SP2
-
Affected
- ≥ NEXO-OS V1000-Release, ≤ NEXO-OS V1500-SP2
-
Affected
- ≥ NEXO-OS V1000-Release, ≤ NEXO-OS V1500-SP2
-
Affected
- ≥ NEXO-OS V1000-Release, ≤ NEXO-OS V1500-SP2
-
Affected
- ≥ NEXO-OS V1000-Release, ≤ NEXO-OS V1500-SP2
-
Affected
- ≥ NEXO-OS V1000-Release, ≤ NEXO-OS V1500-SP2
-
Affected
- ≥ NEXO-OS V1000-Release, ≤ NEXO-OS V1500-SP2
-
Affected
- ≥ NEXO-OS V1000-Release, ≤ NEXO-OS V1500-SP2
-
Affected
- ≥ NEXO-OS V1000-Release, ≤ NEXO-OS V1500-SP2
-
Affected
- ≥ NEXO-OS V1000-Release, ≤ NEXO-OS V1500-SP2
-
Affected
- ≥ NEXO-OS V1000-Release, ≤ NEXO-OS V1500-SP2
-
Affected
- ≥ NEXO-OS V1000-Release, ≤ NEXO-OS V1500-SP2
-
Affected
- ≥ NEXO-OS V1000-Release, ≤ NEXO-OS V1500-SP2
-
Affected
- ≥ NEXO-OS V1000-Release, ≤ NEXO-OS V1500-SP2
-
Affected
- ≥ NEXO-OS V1000-Release, ≤ NEXO-OS V1500-SP2
-
Affected
- ≥ NEXO-OS V1000-Release, ≤ NEXO-OS V1500-SP2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Rexroth | Nexo cordless nutrunner NXA011S-36V (0608842011) | unknown | Affected
|
| Rexroth | Nexo cordless nutrunner NXA011S-36V-B (0608842012) | unknown | Affected
|
| Rexroth | Nexo cordless nutrunner NXA015S-36V (0608842001) | unknown | Affected
|
| Rexroth | Nexo cordless nutrunner NXA015S-36V-B (0608842006) | unknown | Affected
|
| Rexroth | Nexo cordless nutrunner NXA030S-36V (0608842002) | unknown | Affected
|
| Rexroth | Nexo cordless nutrunner NXA030S-36V-B (0608842007) | unknown | Affected
|
| Rexroth | Nexo cordless nutrunner NXA050S-36V (0608842003) | unknown | Affected
|
| Rexroth | Nexo cordless nutrunner NXA050S-36V-B (0608842008) | unknown | Affected
|
| Rexroth | Nexo cordless nutrunner NXA065S-36V (0608842013) | unknown | Affected
|
| Rexroth | Nexo cordless nutrunner NXA065S-36V-B (0608842014) | unknown | Affected
|
| Rexroth | Nexo cordless nutrunner NXP012QD-36V (0608842005) | unknown | Affected
|
| Rexroth | Nexo cordless nutrunner NXP012QD-36V-B (0608842010) | unknown | Affected
|
| Rexroth | Nexo cordless nutrunner NXV012T-36V (0608842015) | unknown | Affected
|
| Rexroth | Nexo cordless nutrunner NXV012T-36V-B (0608842016) | unknown | Affected
|
| Rexroth | Nexo special cordless nutrunner (0608PE2272) | unknown | Affected
|
| Rexroth | Nexo special cordless nutrunner (0608PE2301) | unknown | Affected
|
| Rexroth | Nexo special cordless nutrunner (0608PE2514) | unknown | Affected
|
| Rexroth | Nexo special cordless nutrunner (0608PE2515) | unknown | Affected
|
| Rexroth | Nexo special cordless nutrunner (0608PE2666) | unknown | Affected
|
| Rexroth | Nexo special cordless nutrunner (0608PE2673) | unknown | Affected
|
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-52312 Advisory
- https://psirt.bosch.com/security-advisories/BOSCH-SA-711465.html vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-52312 | Advisory | |
| https://psirt.bosch.com/security-advisories/BOSCH-SA-711465.html | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data