CVE-2023-41372
25.10.2023, 18:17
The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client application, inducing it to connect to an attacker - controlled malicious server.This is possible by forging a valid broadcast intent encrypted with a hardcoded RSA key pairEnginsight
Vendor | Product | Version |
---|---|---|
boschrexroth | ctrlx_hmi_web_panel_wr2107_firmware | * |
boschrexroth | ctrlx_hmi_web_panel_wr2110_firmware | * |
boschrexroth | ctrlx_hmi_web_panel_wr2115_firmware | * |
𝑥
= Vulnerable software versions