Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2023-48255", "assignerOrgId": "c95f66b2-7e7c-41c5-8f09-6f86ec68659c", "state": "PUBLISHED", "assignerShortName": "bosch", "dateReserved": "2023-11-13T13:44:23.705Z", "datePublished": "2024-01-10T13:03:32.151Z", "dateUpdated": "2024-08-02T21:23:39.444Z"}, "containers": {"cna": {"providerMetadata": {"orgId": "c95f66b2-7e7c-41c5-8f09-6f86ec68659c", "shortName": "bosch", "dateUpdated": "2024-01-10T13:03:32.151Z"}, "descriptions": [{"lang": "en", "value": "The vulnerability allows an unauthenticated remote attacker to send malicious network requests containing arbitrary client-side script code and obtain its execution inside a victim\u2019s session via a crafted URL, HTTP request, or simply by waiting for the victim to view the poisoned log."}], "affected": [{"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXA015S-36V (0608842001)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXA030S-36V (0608842002)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXA050S-36V (0608842003)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXP012QD-36V (0608842005)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXA015S-36V-B (0608842006)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXA030S-36V-B (0608842007)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXA050S-36V-B (0608842008)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXP012QD-36V-B (0608842010)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXA011S-36V (0608842011)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXA011S-36V-B (0608842012)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXA065S-36V (0608842013)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXA065S-36V-B (0608842014)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXV012T-36V (0608842015)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo cordless nutrunner NXV012T-36V-B (0608842016)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo special cordless nutrunner (0608PE2272)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo special cordless nutrunner (0608PE2301)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo special cordless nutrunner (0608PE2514)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo special cordless nutrunner (0608PE2515)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo special cordless nutrunner (0608PE2666)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}, {"vendor": "Rexroth", "product": "Nexo special cordless nutrunner (0608PE2673)", "versions": [{"version": "NEXO-OS V1000-Release", "status": "affected", "versionType": "custom", "lessThanOrEqual": "NEXO-OS V1500-SP2"}]}], "problemTypes": [{"descriptions": [{"lang": "en-US", "description": "CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')", "cweId": "CWE-79"}]}], "references": [{"url": "https://psirt.bosch.com/security-advisories/BOSCH-SA-711465.html", "name": "https://psirt.bosch.com/security-advisories/BOSCH-SA-711465.html", "tags": ["vendor-advisory"]}], "metrics": [{"cvssV3_1": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW", "baseScore": 6.3, "baseSeverity": "MEDIUM"}}]}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-02T21:23:39.444Z"}, "title": "CVE Program Container", "references": [{"url": "https://psirt.bosch.com/security-advisories/BOSCH-SA-711465.html", "name": "https://psirt.bosch.com/security-advisories/BOSCH-SA-711465.html", "tags": ["vendor-advisory", "x_transferred"]}]}]}}