CVE-2023-45844

The vulnerability allows a low privileged user that have access to the device when locked in Kiosk mode to install an arbitrary Android application and leverage it to have access to critical device settings such as the device power management or eventually the device secure settings (ADB debug).
References
Link Resource
https://psirt.bosch.com/security-advisories/BOSCH-SA-175607.html Mitigation Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:boschrexroth:ctrlx_hmi_web_panel_wr2107_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:boschrexroth:ctrlx_hmi_web_panel_wr2107:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:boschrexroth:ctrlx_hmi_web_panel_wr2110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:boschrexroth:ctrlx_hmi_web_panel_wr2110:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:boschrexroth:ctrlx_hmi_web_panel_wr2115_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:boschrexroth:ctrlx_hmi_web_panel_wr2115:-:*:*:*:*:*:*:*

History

06 Nov 2023, 14:39

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8
First Time Boschrexroth ctrlx Hmi Web Panel Wr2107
Boschrexroth ctrlx Hmi Web Panel Wr2107 Firmware
Boschrexroth
Boschrexroth ctrlx Hmi Web Panel Wr2115
Boschrexroth ctrlx Hmi Web Panel Wr2115 Firmware
Boschrexroth ctrlx Hmi Web Panel Wr2110
Boschrexroth ctrlx Hmi Web Panel Wr2110 Firmware
References (MISC) https://psirt.bosch.com/security-advisories/BOSCH-SA-175607.html - (MISC) https://psirt.bosch.com/security-advisories/BOSCH-SA-175607.html - Mitigation, Vendor Advisory
CWE NVD-CWE-Other
CPE cpe:2.3:h:boschrexroth:ctrlx_hmi_web_panel_wr2110:-:*:*:*:*:*:*:*
cpe:2.3:h:boschrexroth:ctrlx_hmi_web_panel_wr2107:-:*:*:*:*:*:*:*
cpe:2.3:o:boschrexroth:ctrlx_hmi_web_panel_wr2110_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:boschrexroth:ctrlx_hmi_web_panel_wr2115_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:boschrexroth:ctrlx_hmi_web_panel_wr2107_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:boschrexroth:ctrlx_hmi_web_panel_wr2115:-:*:*:*:*:*:*:*

25 Oct 2023, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-25 18:17

Updated : 2024-09-10 21:35


NVD link : CVE-2023-45844

Mitre link : CVE-2023-45844


JSON object : View

Products Affected

boschrexroth

  • ctrlx_hmi_web_panel_wr2110_firmware
  • ctrlx_hmi_web_panel_wr2110
  • ctrlx_hmi_web_panel_wr2115
  • ctrlx_hmi_web_panel_wr2107_firmware
  • ctrlx_hmi_web_panel_wr2107
  • ctrlx_hmi_web_panel_wr2115_firmware