CVE-2023-41960

The vulnerability allows an unprivileged(untrusted) third-party application to interact with a content-provider unsafely exposed by the Android Agent application, potentially modifying sensitive settings of the Android Client application itself.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:boschrexroth:ctrlx_hmi_web_panel_wr2107_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:boschrexroth:ctrlx_hmi_web_panel_wr2107:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:boschrexroth:ctrlx_hmi_web_panel_wr2110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:boschrexroth:ctrlx_hmi_web_panel_wr2110:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:boschrexroth:ctrlx_hmi_web_panel_wr2115_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:boschrexroth:ctrlx_hmi_web_panel_wr2115:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:21

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-25 18:17

Updated : 2024-11-21 08:21


NVD link : CVE-2023-41960

Mitre link : CVE-2023-41960

CVE.ORG link : CVE-2023-41960


JSON object : View

Products Affected

boschrexroth

  • ctrlx_hmi_web_panel_wr2110
  • ctrlx_hmi_web_panel_wr2107
  • ctrlx_hmi_web_panel_wr2110_firmware
  • ctrlx_hmi_web_panel_wr2115_firmware
  • ctrlx_hmi_web_panel_wr2115
  • ctrlx_hmi_web_panel_wr2107_firmware
CWE
CWE-926

Improper Export of Android Application Components

NVD-CWE-Other