CVE-2023-41960
The vulnerability allows an unprivileged(untrusted) third-party application to interact with a content-provider unsafely exposed by the Android Agent application, potentially modifying sensitive settings of the Android Client application itself.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
- EPSS probability
- 0.07%
- CWE
- CWE-926
- Published
- 2023-10-25
- Last modified
- 2026-03-13
Affected products
- Rexroth ctrlX HMI Web Panel - WR21 (WR2107)
- Rexroth ctrlX HMI Web Panel - WR21 (WR2110)
- Rexroth ctrlX HMI Web Panel - WR21 (WR2115)
Weakness type
Related vulnerabilities
- CVE-2025-5344 — Exposed AIDL service allowing for tampering of system secure settings in Bluebird kiosk application
- CVE-2024-13917 — Intent Injection in Kruger&Matz AppLock application
- CVE-2021-25388 — Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers to install arbitrary a
- CVE-2026-81301 — Ekia File Manager 1.2.7 - Exported ContentProvider allows unauthorized file access
- CVE-2026-18994 — A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distribute
- CVE-2024-13916 — Exposure of Applications' Encryption PINs in Kruger&Matz AppLock
- CVE-2024-13915 — Unrestricted Access to Exported Service in com.pri.factorytest
- CVE-2021-25397 — An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write