Description
The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client application, inducing it to connect to an attacker - controlled malicious server.This is possible by forging a valid broadcast intent encrypted with a hardcoded RSA key pair
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-45874 | The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of the Android Client application, inducing it to connect to an attacker - controlled malicious server.This is possible by forging a valid broadcast intent encrypted with a hardcoded RSA key pair |
References
History
No history.
Status: PUBLISHED
Assigner: bosch
Published:
Updated: 2024-09-12T14:28:34.281Z
Reserved: 2023-10-18T09:35:22.507Z
Link: CVE-2023-41372
Updated: 2024-08-02T19:01:35.280Z
Status : Modified
Published: 2023-10-25T18:17:30.917
Modified: 2024-11-21T08:21:10.570
Link: CVE-2023-41372
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD