CVE-2023-41960 is a low-severity vulnerability affecting Bosch Rexroth ctrlX HMI web panels (WR2107, WR2110, WR2115 series). It allows an unprivileged third-party application to interact unsafely with the Android Agent, potentially modifying sensitive settings of the Android Client application. The CVSS score is 3.3 (LOW), indicating a local attack vector with low complexity and a limited impact on integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:boschrexroth:ctrlx_hmi_web_panel_wr2107_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:boschrexroth:ctrlx_hmi_web_panel_wr2110_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:boschrexroth:ctrlx_hmi_web_panel_wr2115_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple vulnerabilities on ctrlX HMI / WR21
Oct 20, 2023Multiple vulnerabilities on ctrlX HMI / WR21
Oct 20, 2023Multiple vulnerabilities on ctrlX HMI / WR21
Oct 20, 2023Multiple vulnerabilities on ctrlX HMI / WR21
Oct 20, 2023