PT-2024-1492 · Bosch · Bosch Nexo Special Cordless Nutrunner+1

Andrea Palanca

·

Published

2024-01-08

·

Updated

2024-01-16

·

CVE-2023-48256

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Bosch Nexo cordless nutrunner and Bosch Nexo special cordless nutrunner (affected versions not specified)
Description The issue is related to the lack of processing for CRLF sequences in HTTP headers, allowing a remote attacker to inject arbitrary HTTP response headers or manipulate HTTP response bodies within a victim's session. This can be achieved via a specially crafted URL or HTTP request.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2024-01000
CVE-2023-48256

Affected Products

Bosch Nexo Cordless Nutrunner
Bosch Nexo Special Cordless Nutrunner