CVE-2023-45851 describes a critical vulnerability in Bosch Rexroth ctrlX HMI web panels (WR2107, WR2110, WR2115 series) where the Android Client application fails to authenticate the MQTT broker it connects to. This allows an adjacent attacker to redirect the client to a malicious broker, enabling the injection of fake messages to the HMI device. With a CVSS score of 8.8 (High), the vulnerability presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and community discussion is minimal, the potential for severe disruption to industrial control systems remains.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:boschrexroth:ctrlx_hmi_web_panel_wr2107_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:boschrexroth:ctrlx_hmi_web_panel_wr2110_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:boschrexroth:ctrlx_hmi_web_panel_wr2115_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple vulnerabilities on ctrlX HMI / WR21
Oct 20, 2023Multiple vulnerabilities on ctrlX HMI / WR21
Oct 20, 2023Multiple vulnerabilities on ctrlX HMI / WR21
Oct 20, 2023Multiple vulnerabilities on ctrlX HMI / WR21
Oct 20, 2023