Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2023-48253", "assignerOrgId": "c95f66b2-7e7c-41c5-8f09-6f86ec68659c", "state": "PUBLISHED", "assignerShortName": "bosch", "dateReserved": "2023-11-13T13:44:23.705Z", "datePublished": "2024-01-10T13:02:19.652Z", "dateUpdated": "2024-08-02T21:23:39.464Z"}, "containers": {"cna": {"providerMetadata": {"orgId": "c95f66b2-7e7c-41c5-8f09-6f86ec68659c", "shortName": "bosch", "dateUpdated": "2024-01-10T13:02:19.652Z"}, "descriptions": [{"lang": "en", "value": "The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication database via a crafted HTTP request.\r\nBy abusing this vulnerability it is possible to exfiltrate other users\u2019 password hashes or update them with arbitrary values and access their accounts."}], "affected": [{"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXA015S-36V (0608842001)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXA030S-36V (0608842002)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXA050S-36V (0608842003)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXP012QD-36V (0608842005)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXA015S-36V-B (0608842006)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXA030S-36V-B (0608842007)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXA050S-36V-B (0608842008)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXP012QD-36V-B (0608842010)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXA011S-36V (0608842011)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXA011S-36V-B (0608842012)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXA065S-36V (0608842013)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXA065S-36V-B (0608842014)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXV012T-36V (0608842015)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXV012T-36V-B (0608842016)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo special cordless nutrunner (0608PE2272)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo special cordless nutrunner (0608PE2301)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo special cordless nutrunner (0608PE2514)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo special cordless nutrunner (0608PE2515)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo special cordless nutrunner (0608PE2666)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo special cordless nutrunner (0608PE2673)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}], "problemTypes": [{"descriptions": [{"lang": "en-US", "description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')", "cweId": "CWE-89"}]}], "references": [{"url": "https://psirt.bosch.com/security-advisories/BOSCH-SA-711465.html", "name": "https://psirt.bosch.com/security-advisories/BOSCH-SA-711465.html", "tags": ["vendor-advisory"]}], "metrics": [{"cvssV3_1": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH"}}]}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-02T21:23:39.464Z"}, "title": "CVE Program Container", "references": [{"url": "https://psirt.bosch.com/security-advisories/BOSCH-SA-711465.html", "name": "https://psirt.bosch.com/security-advisories/BOSCH-SA-711465.html", "tags": ["vendor-advisory", "x_transferred"]}]}]}}