CVE-2023-1750
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/04/2023
Last modified:
07/11/2023
Description
The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a valid NexxHome deviceId could retrieve device history, set device settings, and retrieve device information.
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:getnexx:nxal-100_firmware:*:*:*:*:*:*:*:* | nxal100v-p1-9-1 (including) | |
| cpe:2.3:h:getnexx:nxal-100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:getnexx:nxg-100b_firmware:*:*:*:*:*:*:*:* | nxg100bv-p3-4-1 (including) | |
| cpe:2.3:h:getnexx:nxg-100b:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:getnexx:nxpg-100w_firmware:*:*:*:*:*:*:*:* | nxpg100cv4-0-0 (including) | |
| cpe:2.3:h:getnexx:nxpg-100w:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:getnexx:nxg-200_firmware:*:*:*:*:*:*:*:* | nxg200v-p3-4-1 (including) | |
| cpe:2.3:h:getnexx:nxg-200:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



