← Vulnerability feed

Vulnerability record · CVE-2023-3643 · published 12 July 2023

CVE-2023-3643: Boss Mini firmware path argument file inclusion

Carel · Boss Mini Firmware

Boss Mini 1.4.0 Build 6221 contains a critical file inclusion flaw in boss/servlet/document, where manipulation of the path argument lets an attacker include unintended files. The issue is remotely reachable and a public exploit has been disclosed, so unpatched internet-facing instances are at immediate risk.

9.8 CVSS 3.1 Critical EPSS 75% · top 0.5% CWE-73 · CWE-73
9.8CVSS 3.1 base score, v2 7.5
75%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233889 was assigned to this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or interaction required, a public exploit, and a very high EPSS probability make this an urgent remote file inclusion risk.

What it is

Boss Mini 1.4.0 Build 6221 contains a critical file inclusion flaw in boss/servlet/document, where manipulation of the path argument lets an attacker include unintended files. The issue is remotely reachable and a public exploit has been disclosed, so unpatched internet-facing instances are at immediate risk.

Impact

An attacker can read or include files outside the intended document scope, potentially exposing sensitive data or enabling further code execution depending on server configuration. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

The flaw is reached over the network via the boss/servlet/document endpoint by supplying a crafted path argument. The CVSS vector shows no privileges or user interaction required (PR:N, UI:N).

Exploitation

A public exploit is referenced and EPSS is very high at 0.75363 (99.49th percentile), but the CVE is not listed in CISA KEV and no ransomware use is documented.

What to do

  • Apply the vendor fix for Boss Mini 1.4.0 Build 6221 or upgrade to a patched release as soon as one is available.
  • Restrict network access to the boss/servlet/document endpoint to trusted management networks only.
  • Validate and canonicalize the path parameter, rejecting traversal sequences and absolute paths.
  • Run the Boss Mini service with least privilege and confine it to a directory with no sensitive files.
  • Monitor vendor and VDB-233889 advisories for updated remediation guidance.

Detection

  • Inspect web logs for requests to boss/servlet/document with path parameters containing ../, encoded traversal, or absolute file paths.
  • Alert on unusual file reads or errors from the Boss Mini process that reference files outside its expected document directory.
  • Correlate outbound or internal access to the Boss Mini management interface from unexpected source IPs.
  • Search for known public exploit payload patterns against the document servlet in IDS/IPS or WAF telemetry.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-3643 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2022-34827Carel boss mini firmware improper access control vulnerabilityCarel Boss Mini 1.5.0 has Improper Access Control.EPSS 0.82%8.8CVE-2025-33053Microsoft Windows WebDAV Internet Shortcut File Path Control RCEWindows Internet Shortcut (.url) files allow external control of a file name or path, which an unauthorized attacker can abuse to execute code over a…KEVEPSS 87%analysed5.4CVE-2025-24054Windows NTLM file path control allows spoofingWindows NTLM mishandles externally controlled file names or paths, letting an unauthorized attacker perform spoofing over a network. The flaw affects…KEVEPSS 59%analysed7.1CVE-2025-0111PAN-OS authenticated file read via management web interfacePAN-OS contains an authenticated file read vulnerability that lets a user with network access to the management web interface read files on the PAN-O…KEVEPSS 2.0%analysed6.5CVE-2024-43451Microsoft Windows NTLMv2 hash disclosure via spoofingCVE-2024-43451 is an NTLM hash disclosure spoofing vulnerability in Microsoft Windows. An attacker can induce a victim to disclose their NTLMv2 hash,…KEVEPSS 84%analysed4.3CVE-2018-13374FortiOS and FortiADC access control flaw exposes LDAP credentialsFortiOS (6.0.2, 5.6.7 and earlier) and FortiADC (6.1.0, 6.0.0-6.0.1, 5.4.0-5.4.4) contain an improper access control flaw. An attacker can redirect a…KEVEPSS 38%analysed7.8CVE-2022-22960VMware Workspace ONE Access and related products local privilege escalationVMware Workspace ONE Access, Identity Manager, vRealize Automation and related products ship support scripts with incorrect permission assignments (C…KEVEPSS 36%analysed9.8CVE-2020-1631Juniper Junos OS J-Web HTTP service path traversal and local file inclusionThe HTTP/HTTPS service behind J-Web, Web Authentication, Dynamic-VPN, Firewall Authentication Pass-Through with Web-Redirect, and ZTP in Junos OS doe…KEVEPSS 4.8%analysed

Source: NIST National Vulnerability Database (record CVE-2023-3643), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.