60
CVE-2023-48242
—CVSS 3.1
6.5 medium
EPSS
<1%p54
Published
()
Modified
Description
The vulnerability allows an authenticated remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.
- Vendors
- bosch
- Products
- nexo-os
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N