PT-2024-13559 · Rexroth+1 · Nexo Cordless Nutrunner Nxa011S-36V+8

Andrea Palanca

·

Published

2024-01-10

·

Updated

2024-01-17

·

CVE-2023-48248

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Software (affected versions not specified)
Description The issue allows an authenticated remote attacker to upload a malicious file to the SD card containing arbitrary client-side script code and obtain its execution inside a victim’s session via a crafted URL, HTTP request, or simply by waiting for the victim to view the poisoned file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-48248

Affected Products

Nexo Cordless Nutrunner Nxa011S-36V
Nexo Cordless Nutrunner Nxa015S-36V
Nexo Cordless Nutrunner Nxa030S-36V
Nexo Cordless Nutrunner Nxa050S-36V
Nexo Cordless Nutrunner Nxa065S-36V
Nexo Cordless Nutrunner Nxp012Qd-36V
Nexo Cordless Nutrunner Nxp012Qd-36V-B
Bosch Nexo Special Cordless Nutrunner
Nexo-Os