
CVE-2023-3643: A critical path traversal flaw in CAREL Boss-Mini v1.4.0 allows unauthenticated file reads on HVAC and refrigeration systems. https://www.redsecuretech.co.uk/blog/post/critical-lfi-bug-hits-carel-boss-mini-industrial-controllers/1001 #CyberSecurity #OTSecurity #ICS #CVE #CAREL #HVAC #IndustrialControl #PathTraversal #FirmwareUpdate #InfoSec https://t.co/tLGxVJ0wWO
Post summary
CVE-2023-3643 is a critical path traversal vulnerability in CAREL Boss‑Mini v1.4.0 that enables unauthenticated file reads on HVAC and refrigeration systems; the tweet provides a brief disclosure but no PoC, exploit code, or patch details.

