Description
The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client application, inducing it to connect to an attacker - controlled malicious server.This is possible by forging a valid broadcast intent encrypted with a hardcoded RSA key pair
Published: 2023-10-25
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-45874 The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client application, inducing it to connect to an attacker - controlled malicious server.This is possible by forging a valid broadcast intent encrypted with a hardcoded RSA key pair
History

No history.

Subscriptions

Boschrexroth Ctrlx Hmi Web Panel Wr2107 Ctrlx Hmi Web Panel Wr2107 Firmware Ctrlx Hmi Web Panel Wr2110 Ctrlx Hmi Web Panel Wr2110 Firmware Ctrlx Hmi Web Panel Wr2115 Ctrlx Hmi Web Panel Wr2115 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: bosch

Published:

Updated: 2024-09-12T14:28:34.281Z

Reserved: 2023-10-18T09:35:22.507Z

Link: CVE-2023-41372

cve-icon Vulnrichment

Updated: 2024-08-02T19:01:35.280Z

cve-icon NVD

Status : Modified

Published: 2023-10-25T18:17:30.917

Modified: 2024-11-21T08:21:10.570

Link: CVE-2023-41372

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses