S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 11, 2026

CVE-2023-3643 Scanner

CVE-2023-3643 Scanner - Local File Inclusion (LFI) vulnerability in CAREL Boss Mini

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.9k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-3643
9.8
CVSShigh
Exploitable remotely over the internet · no authentication required.

A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233889 was assigned to this vulnerability.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Boss Miniby n/a
1.4.0 Build 6221
Updated Aug 22, 2026View on NVD →
Detail

CAREL Boss Mini is a sophisticated software platform used in industrial and building automation environments. Developed by CAREL, this product is widely implemented in settings requiring precise environmental control, such as HVAC systems and refrigeration. Its primary purpose is to manage and monitor various connected devices, providing users with real-time data and control capabilities. Industries ranging from manufacturing to commercial real estate depend on this system for seamless operation of their critical infrastructure. The platform allows for both local and remote management, making it versatile for various operational needs. As such, maintaining its security is crucial due to its integral role in managing critical systems.

The detected vulnerability in CAREL Boss Mini involves Local File Inclusion (LFI), a critical security flaw. This vulnerability can potentially allow attackers to include and execute files from the local server, potentially leading to severe security compromises. The flaw lies in the manipulation of file paths within the software's endpoint, specifically through the 'path' parameter, exposing it to malicious input. As a result, unauthorized actors may inject or execute files, gaining access to sensitive data or further infiltrating the network. Remote access is a prerequisite for exploiting this vulnerability, which could lead to unauthorized access or control over the system. Consequently, this flaw requires urgent remedy to avert potential breaches.

In technical terms, the vulnerability arises from improper handling of the 'path' parameter in the endpoint "/boss/servlet/document". Attackers can craft requests to manipulate this parameter, causing the server to process unintended file paths. Specifically, the system may process files like '/etc/passwd', leading to exposure of sensitive information. This type of vulnerability can extend beyond information retrieval, enabling further actions like remote code execution. A successful exploitation returns a status code of 200, indicating that the attack was processed and confirming the vulnerability's presence. Such improper file handling could result in severe system breaches without appropriate access controls and verification.

Exploiting this vulnerability could have drastic effects on affected systems. Malicious individuals might gain unauthorized access to sensitive files, potentially leading to data leaks or unauthorized data modifications. In the worst-case scenario, it could open a pathway for executing malicious code, compromising the entire system and allowing for full control over the affected infrastructure. Such exploitation could disrupt operations, corrupt critical data, or compromise system integrity, posing significant threats to associated industrial processes. Therefore, addressing this vulnerability is imperative to prevent any operational disruption or data breach.

REFERENCES

Solution Advice
  • Update CAREL Boss Mini to the latest version to ensure all security patches are applied.
  • Regularly audit systems for any unauthorized file inclusions or modifications.
  • Implement robust input validation mechanisms to prevent malicious input exploitation.
  • Restrict remote access to essential services only, minimizing exposure to unauthorized entities.
  • Conduct periodic security assessments and vulnerability scans to detect and mitigate potential exploits proactively.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.