Vulnerability Details CVE-2023-1750
The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a valid NexxHome deviceId could retrieve device history, set device settings, and retrieve device information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 44.1%
CVSS Severity
CVSS v3 Score 7.1
Products affected by CVE-2023-1750
-
cpe:2.3:h:getnexx:nxal-100:-
-
cpe:2.3:h:getnexx:nxg-100b:-
-
cpe:2.3:h:getnexx:nxg-200:-
-
cpe:2.3:h:getnexx:nxpg-100w:-
-
cpe:2.3:o:getnexx:nxal-100_firmware:*
-
cpe:2.3:o:getnexx:nxg-100b_firmware:*
-
cpe:2.3:o:getnexx:nxg-200_firmware:*
-
cpe:2.3:o:getnexx:nxpg-100w_firmware:*