CVE-2023-41372
25.10.2023, 18:17
The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client application, inducing it to connect to an attacker - controlled malicious server.This is possible by forging a valid broadcast intent encrypted with a hardcoded RSA key pairEnginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| boschrexroth | ctrlx_hmi_web_panel_wr2107_firmware | * |
| boschrexroth | ctrlx_hmi_web_panel_wr2110_firmware | * |
| boschrexroth | ctrlx_hmi_web_panel_wr2115_firmware | * |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| boschrexroth | ctrlx_hmi_web_panel_wr2107 | 𝑥 < * | ADP |
| boschrexroth | ctrlx_hmi_web_panel_wr2110 | 𝑥 < * | ADP |
| boschrexroth | ctrlx_hmi_web_panel_wr2115 | 𝑥 < * | ADP |