CVE-2023-3643Disclosure(carel / boss_mini)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233889 was assigned to this vulnerability.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • boss_mini
  • boss_mini_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-06); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
boss_miniboss_mini_firmware

2 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-06: 1Mentions · 2026-03-11: 1PoC Mentioned / Linked · 2026-03-11: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-11: 103-0603-11
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Red Secure Tech Ltd.@redsecuretech
    Disclosure

    CVE-2023-3643: A critical path traversal flaw in CAREL Boss-Mini v1.4.0 allows unauthenticated file reads on HVAC and refrigeration systems. https://www.redsecuretech.co.uk/blog/post/critical-lfi-bug-hits-carel-boss-mini-industrial-controllers/1001 #CyberSecurity #OTSecurity #ICS #CVE #CAREL #HVAC #IndustrialControl #PathTraversal #FirmwareUpdate #InfoSec https://t.co/tLGxVJ0wWO

    Post summary

    CVE-2023-3643 is a critical path traversal vulnerability in CAREL Boss‑Mini v1.4.0 that enables unauthenticated file reads on HVAC and refrigeration systems; the tweet provides a brief disclosure but no PoC, exploit code, or patch details.

    0101055
    40 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2023-3643 - critical 🚨 CAREL Boss Mini <= 1.4.0 - Local File Inclusion > Boss Mini 1.4.0 Build 6221 contains a file inclusion caused by manipulation of the 'p... 👾 https://cloud.projectdiscovery.io/library/CVE-2023-3643 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces a critical Local File Inclusion vulnerability (CVE-2023-3643) in CAREL Boss Mini, providing basic technical details and linking to a library page that likely contains PoC code, but does not describe active exploitation, patches, or false positives.

    00000120
    902 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWcarelboss_mini---
OScarelboss_mini_firmware1.4.0--

Explore more