Vulnerability Details CVE-2023-1749
The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a valid NexxHome deviceId could send API requests that the affected devices would execute.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 36.8%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2023-1749
-
cpe:2.3:h:getnexx:nxal-100:-
-
cpe:2.3:h:getnexx:nxg-100b:-
-
cpe:2.3:h:getnexx:nxg-200:-
-
cpe:2.3:h:getnexx:nxpg-100w:-
-
cpe:2.3:o:getnexx:nxal-100_firmware:*
-
cpe:2.3:o:getnexx:nxg-100b_firmware:*
-
cpe:2.3:o:getnexx:nxg-200_firmware:*
-
cpe:2.3:o:getnexx:nxpg-100w_firmware:*