Bosch
Bosch Nexo-os: vulnerabilidades y CVE
Bosch Nexo-os tiene 25 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE25
Últimos 12 meses0
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-48266 | Crítica (9.8) | 0.76% | — | 10 ene 2024 | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request. |
| CVE-2023-48265 | Crítica (9.8) | 0.76% | — | 10 ene 2024 | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request. |
| CVE-2023-48264 | Crítica (9.8) | 0.76% | — | 10 ene 2024 | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request. |
| CVE-2023-48263 | Crítica (9.8) | 0.76% | — | 10 ene 2024 | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request. |
| CVE-2023-48262 | Crítica (9.8) | 0.76% | — | 10 ene 2024 | The vulnerability allows an unauthenticated remote attacker to perform a Denial-of-Service (DoS) attack or, possibly, obtain Remote Code Execution (RCE) via a crafted network request. |
| CVE-2023-48261 | Alta (7.5) | 0.62% | — | 10 ene 2024 | The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request. |
| CVE-2023-48260 | Alta (7.5) | 0.62% | — | 10 ene 2024 | The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request. |
| CVE-2023-48259 | Alta (7.5) | 0.62% | — | 10 ene 2024 | The vulnerability allows a remote unauthenticated attacker to read arbitrary content of the results database via a crafted HTTP request. |
| CVE-2023-48258 | Alta (8.1) | 0.24% | — | 10 ene 2024 | The vulnerability allows a remote attacker to delete arbitrary files on the file system via a crafted URL or HTTP request through a victim’s session. |
| CVE-2023-48257 | Alta (8.8) | 0.54% | — | 10 ene 2024 | The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) with root privileges on the device. The vulnerability can be exploited directly by… |
| CVE-2023-48256 | Media (6.3) | 0.30% | — | 10 ene 2024 | The vulnerability allows a remote attacker to inject arbitrary HTTP response headers or manipulate HTTP response bodies inside a victim’s session via a crafted URL or HTTP request. |
| CVE-2023-48255 | Media (6.1) | 0.50% | — | 10 ene 2024 | The vulnerability allows an unauthenticated remote attacker to send malicious network requests containing arbitrary client-side script code and obtain its execution inside a victim’s session via a crafted URL, HTTP… |
| CVE-2023-48254 | Media (6.1) | 0.31% | — | 10 ene 2024 | The vulnerability allows a remote attacker to inject and execute arbitrary client-side script code inside a victim’s session via a crafted URL or HTTP request. |
| CVE-2023-48253 | Alta (8.8) | 0.87% | — | 10 ene 2024 | The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication database via a crafted HTTP request. By abusing this vulnerability it is possible to exfiltrate other… |
| CVE-2023-48252 | Alta (8.8) | 0.64% | — | 10 ene 2024 | The vulnerability allows an authenticated remote attacker to perform actions exceeding their authorized access via crafted HTTP requests. |
| CVE-2023-48251 | Crítica (9.8) | 0.56% | — | 10 ene 2024 | The vulnerability allows a remote attacker to authenticate to the SSH service with root privileges through a hidden hard-coded account. |
| CVE-2023-48250 | Crítica (9.8) | 0.57% | — | 10 ene 2024 | The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded accounts. |
| CVE-2023-48249 | Media (6.5) | 0.78% | — | 10 ene 2024 | The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this… |
| CVE-2023-48248 | Media (5.4) | 0.44% | — | 10 ene 2024 | The vulnerability allows an authenticated remote attacker to upload a malicious file to the SD card containing arbitrary client-side script code and obtain its execution inside a victim’s session via a crafted URL, HTTP… |
| CVE-2023-48247 | Alta (7.5) | 0.56% | — | 10 ene 2024 | The vulnerability allows an unauthenticated remote attacker to read arbitrary files under the context of the application OS user (“root”) via a crafted HTTP request. |
| CVE-2023-48246 | Media (6.5) | 0.78% | — | 10 ene 2024 | The vulnerability allows a remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. |
| CVE-2023-48245 | Crítica (9.8) | 0.63% | — | 10 ene 2024 | The vulnerability allows an unauthenticated remote attacker to upload arbitrary files under the context of the application OS user (“root”) via a crafted HTTP request. |
| CVE-2023-48244 | Media (6.1) | 0.31% | — | 10 ene 2024 | The vulnerability allows a remote attacker to inject and execute arbitrary client-side script code inside a victim’s session via a crafted URL or HTTP request. |
| CVE-2023-48243 | Alta (8.8) | 1.1% | — | 10 ene 2024 | The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is… |
| CVE-2023-48242 | Media (6.5) | 0.78% | — | 10 ene 2024 | The vulnerability allows an authenticated remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. |
Otros productos de Bosch
Video Recording Manager · 10Bosch Video Management System · 8Cpp13 Firmware · 8Cpp6 Firmware · 7Cpp7 Firmware · 7Cpp7.3 Firmware · 7Video Management System · 7Smart Home Controller Firmware · 6Building Integration System · 6Infotainment ECU · 6Access Professional Edition · 5Configuration Manager · 5