PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2023-3643

7.3
CVSShigh
Exploitable remotely over the internet · no authentication required.
Description

A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233889 was assigned to this vulnerability.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
boss mini
Updated Sep 18, 2026View on NVD →
S4E scanner

CAREL Boss Mini <= 1.4.0 - Local File Inclusion

Boss Mini 1.4.0 Build 6221 contains a file inclusion caused by manipulation of the 'path' argument in boss/servlet/document, letting remote attackers include arbitrary files, exploit requires remote access. References: https://nvd.nist.gov/vuln/detail/CVE-2023-3643 https://www.cisa.gov/news-events/ics-advisories/icsa-24-172-02 https://vuldb.com/?id.233889 https://www.exploit-db.com/exploits/52482 Remediation: Update to the latest version of Boss Mini or apply security patches provided by the vendor.

Used 2.7k times · domain, subdomain, ipv4

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →