CVE-2023-3643

HIGH NUCLEI

Boss Mini 1.4.0 Build 6221 - File Inclusion

Title source: llm

Description

A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233889 was assigned to this vulnerability.

Nuclei Templates (1)

CAREL Boss Mini <= 1.4.0 - Local File Inclusion
CRITICALVERIFIEDby Kazgangap
FOFA: icon_hash=="1092427843"

Scores

CVSS v3 7.3
EPSS 0.1911
EPSS Percentile 95.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-73
Status published

Affected Products (1)

carel/boss_mini_firmware

Timeline

Published Jul 12, 2023
Tracked Since Feb 18, 2026