Search

Find a vulnerability

Search criteria

    20 vulnerabilities by sick

    CVE-2024-10776 (GCVE-0-2024-10776)

    Vulnerability from cvelistv5 – Published: 2024-12-06 12:38 – Updated: 2024-12-09 14:06
    VLAI
    Title
    SICK InspectorP61x and SICK InspectorP62x: missing authentication
    Summary
    Lua apps can be deployed, removed, started, reloaded or stopped without authorization via AppManager. This allows an attacker to remove legitimate apps creating a DoS attack, read and write files or load apps that use all features of the product available to a customer.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-12-06 18:45 UTC
    CWE
    • CWE-306 - Missing Authentication for Critical Function
    Assigner
    References
    URL Tags
    https://sick.com/psirt x_SICK PSIRT Website
    https://cdn.sick.com/media/docs/1/11/411/Special_… x_SICK Operating Guidelines
    https://www.cisa.gov/resources-tools/resources/ic… x_ICS-CERT recommended practices on Industrial Security
    https://www.first.org/cvss/calculator/3.1 x_CVSS v3.1 Calculator
    https://www.sick.com/.well-known/csaf/white/2024/… vendor-advisory
    https://www.sick.com/.well-known/csaf/white/2024/… vendor-advisoryx_csaf
    Impacted products
    Vendor Product Version
    SICK AG SICK InspectorP61x Affected: 0 , < <5.0.0 (custom)
    Create a notification for this product.
    SICK AG SICK InspectorP62x Affected: 0 , < <5.0.0 (custom)
    Create a notification for this product.
    sick inspector61x_firmware Affected: 0 , < 5.0.0 (custom)
        cpe:2.3:o:sick:inspector61x_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    sick inspector62x_firmware Affected: 0 , < 5.0.0 (custom)
        cpe:2.3:o:sick:inspector62x_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-12-06 12:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:sick:inspector61x_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "inspector61x_firmware",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThan": "5.0.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:sick:inspector62x_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "inspector62x_firmware",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThan": "5.0.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-10776",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-12-06T18:45:18.244404Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-09T14:06:40.506Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "SICK InspectorP61x",
              "vendor": "SICK AG",
              "versions": [
                {
                  "lessThan": "\u003c5.0.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "SICK InspectorP62x",
              "vendor": "SICK AG",
              "versions": [
                {
                  "lessThan": "\u003c5.0.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Manuel Stotz"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Tobias Jaeger"
            }
          ],
          "datePublic": "2024-12-06T12:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Lua apps can be deployed, removed, started, reloaded or stopped without authorization via\nAppManager. This allows an attacker to remove legitimate apps creating a DoS attack, read and write\nfiles or load apps that use all features of the product available to a customer."
                }
              ],
              "value": "Lua apps can be deployed, removed, started, reloaded or stopped without authorization via\nAppManager. This allows an attacker to remove legitimate apps creating a DoS attack, read and write\nfiles or load apps that use all features of the product available to a customer."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306 Missing Authentication for Critical Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-12-06T12:38:55.781Z",
            "orgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
            "shortName": "SICK AG"
          },
          "references": [
            {
              "tags": [
                "x_SICK PSIRT Website"
              ],
              "url": "https://sick.com/psirt"
            },
            {
              "tags": [
                "x_SICK Operating Guidelines"
              ],
              "url": "https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF"
            },
            {
              "tags": [
                "x_ICS-CERT recommended practices on Industrial Security"
              ],
              "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices"
            },
            {
              "tags": [
                "x_CVSS v3.1 Calculator"
              ],
              "url": "https://www.first.org/cvss/calculator/3.1"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.pdf"
            },
            {
              "tags": [
                "vendor-advisory",
                "x_csaf"
              ],
              "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.json"
            }
          ],
          "source": {
            "advisory": "SCA-2024-0006",
            "discovery": "EXTERNAL"
          },
          "title": "SICK InspectorP61x and SICK InspectorP62x: missing authentication",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Customers are strongly recommended to upgrade to the latest release. Furthermore, the\napp development should be done in a trusted environment. After the development, app management\nshould be disabled"
                }
              ],
              "value": "Customers are strongly recommended to upgrade to the latest release. Furthermore, the\napp development should be done in a trusted environment. After the development, app management\nshould be disabled"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
        "assignerShortName": "SICK AG",
        "cveId": "CVE-2024-10776",
        "datePublished": "2024-12-06T12:38:55.781Z",
        "dateReserved": "2024-11-04T13:08:11.677Z",
        "dateUpdated": "2024-12-09T14:06:40.506Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-10774 (GCVE-0-2024-10774)

    Vulnerability from cvelistv5 – Published: 2024-12-06 12:35 – Updated: 2024-12-09 14:48
    VLAI
    Title
    SICK InspectorP61x and SICK InspectorP62x have unauthenticated CROWN APIs
    Summary
    Unauthenticated CROWN APIs allow access to critical functions. This leads to the accessibility of large parts of the web application without authentication.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-12-09 14:47 UTC
    CWE
    • CWE-306 - Missing Authentication for Critical Function
    Assigner
    References
    URL Tags
    https://sick.com/psirt x_SICK PSIRT Website
    https://cdn.sick.com/media/docs/1/11/411/Special_… x_SICK Operating Guidelines
    https://www.cisa.gov/resources-tools/resources/ic… x_ICS-CERT recommended practices on Industrial Security
    https://www.first.org/cvss/calculator/3.1 x_CVSS v3.1 Calculator
    https://www.sick.com/.well-known/csaf/white/2024/… vendor-advisory
    https://www.sick.com/.well-known/csaf/white/2024/… vendor-advisoryx_csaf
    Impacted products
    Vendor Product Version
    SICK AG SICK InspectorP61x Affected: 0 , < <5.0.0 (custom)
    Create a notification for this product.
    SICK AG SICK InspectorP62x Affected: 0 , < <5.0.0 (custom)
    Create a notification for this product.
    sick inspector61x_firmware Affected: 0 , < 5.0.0 (custom)
        cpe:2.3:o:sick:inspector61x_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    sick inspector62x_firmware Affected: 0 , < 5.0.0 (custom)
        cpe:2.3:o:sick:inspector62x_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-12-06 12:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:sick:inspector61x_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "inspector61x_firmware",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThan": "5.0.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:sick:inspector62x_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "inspector62x_firmware",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThan": "5.0.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-10774",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-12-09T14:47:57.127996Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-09T14:48:43.228Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "SICK InspectorP61x",
              "vendor": "SICK AG",
              "versions": [
                {
                  "lessThan": "\u003c5.0.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "SICK InspectorP62x",
              "vendor": "SICK AG",
              "versions": [
                {
                  "lessThan": "\u003c5.0.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Manuel Stotz"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Tobias Jaeger"
            }
          ],
          "datePublic": "2024-12-06T12:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Unauthenticated CROWN APIs allow access to critical functions. This leads to the accessibility of large parts of the web application without authentication."
                }
              ],
              "value": "Unauthenticated CROWN APIs allow access to critical functions. This leads to the accessibility of large parts of the web application without authentication."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306 Missing Authentication for Critical Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-12-06T12:35:03.327Z",
            "orgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
            "shortName": "SICK AG"
          },
          "references": [
            {
              "tags": [
                "x_SICK PSIRT Website"
              ],
              "url": "https://sick.com/psirt"
            },
            {
              "tags": [
                "x_SICK Operating Guidelines"
              ],
              "url": "https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF"
            },
            {
              "tags": [
                "x_ICS-CERT recommended practices on Industrial Security"
              ],
              "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices"
            },
            {
              "tags": [
                "x_CVSS v3.1 Calculator"
              ],
              "url": "https://www.first.org/cvss/calculator/3.1"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.pdf"
            },
            {
              "tags": [
                "vendor-advisory",
                "x_csaf"
              ],
              "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.json"
            }
          ],
          "source": {
            "advisory": "SCA-2024-0006",
            "discovery": "EXTERNAL"
          },
          "title": "SICK InspectorP61x and SICK InspectorP62x have unauthenticated CROWN APIs",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "For InspectorP61x and InspectorP62x: \n\nCustomers are strongly recommended to upgrade to the latest release. Furthermore, the\napp development for which the CROWN API is required should be done in a trusted environment. As\nsoon as the device is used productively with the custom-developed apps, the CROWN API should be\ndeactivated."
                }
              ],
              "value": "For InspectorP61x and InspectorP62x: \n\nCustomers are strongly recommended to upgrade to the latest release. Furthermore, the\napp development for which the CROWN API is required should be done in a trusted environment. As\nsoon as the device is used productively with the custom-developed apps, the CROWN API should be\ndeactivated."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
        "assignerShortName": "SICK AG",
        "cveId": "CVE-2024-10774",
        "datePublished": "2024-12-06T12:35:03.327Z",
        "dateReserved": "2024-11-04T13:07:02.373Z",
        "dateUpdated": "2024-12-09T14:48:43.228Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-10773 (GCVE-0-2024-10773)

    Vulnerability from cvelistv5 – Published: 2024-12-06 12:31 – Updated: 2024-12-09 14:44
    VLAI
    Title
    SICK InspectorP61x, SICK InspectorP62x and SICK TiM3xx are vulnerable for pass-the-hash attacks
    Summary
    The product is vulnerable to pass-the-hash attacks in combination with hardcoded credentials of hidden user levels. This means that an attacker can log in with the hidden user levels and gain full access to the device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-12-09 14:37 UTC
    CWE
    Assigner
    References
    URL Tags
    https://sick.com/psirt x_SICK PSIRT Website
    https://cdn.sick.com/media/docs/1/11/411/Special_… x_SICK Operating Guidelines
    https://www.cisa.gov/resources-tools/resources/ic… x_ICS-CERT recommended practices on Industrial Security
    https://www.first.org/cvss/calculator/3.1 x_CVSS v3.1 Calculator
    https://www.sick.com/.well-known/csaf/white/2024/… vendor-advisory
    https://www.sick.com/.well-known/csaf/white/2024/… vendor-advisoryx_csaf
    Impacted products
    Vendor Product Version
    SICK AG SICK InspectorP61x Affected: 0 , < <5.0.0 (custom)
    Create a notification for this product.
    SICK AG SICK InspectorP62x Affected: 0 , < <5.0.0 (custom)
    Create a notification for this product.
    SICK AG TiM3xx Affected: 0 , < <5.10.0 (custom)
    Create a notification for this product.
    sick inspector61x_firmware Affected: 0 , < 5.0.0 (custom)
        cpe:2.3:o:sick:inspector61x_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    sick inspector62x_firmware Affected: 0 , < 5.0.0 (custom)
        cpe:2.3:o:sick:inspector62x_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    sick tim3xx Affected: 0 , < 5.10.0 (custom)
        cpe:2.3:a:sick:tim3xx:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-12-06 12:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:sick:inspector61x_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "inspector61x_firmware",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThan": "5.0.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:sick:inspector62x_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "inspector62x_firmware",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThan": "5.0.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:sick:tim3xx:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "tim3xx",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThan": "5.10.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-10773",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-12-09T14:37:48.545525Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-09T14:44:36.597Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "SICK InspectorP61x",
              "vendor": "SICK AG",
              "versions": [
                {
                  "lessThan": "\u003c5.0.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "SICK InspectorP62x",
              "vendor": "SICK AG",
              "versions": [
                {
                  "lessThan": "\u003c5.0.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TiM3xx",
              "vendor": "SICK AG",
              "versions": [
                {
                  "lessThan": "\u003c5.10.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Manuel Stotz"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Tobias Jaeger"
            }
          ],
          "datePublic": "2024-12-06T12:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The product is vulnerable to pass-the-hash attacks in combination with hardcoded credentials of hidden user levels. This means that an attacker can log in with the hidden user levels and gain\nfull access to the device."
                }
              ],
              "value": "The product is vulnerable to pass-the-hash attacks in combination with hardcoded credentials of hidden user levels. This means that an attacker can log in with the hidden user levels and gain\nfull access to the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-912",
                  "description": "CWE-912 Hidden Functionality",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-12-06T12:31:10.776Z",
            "orgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
            "shortName": "SICK AG"
          },
          "references": [
            {
              "tags": [
                "x_SICK PSIRT Website"
              ],
              "url": "https://sick.com/psirt"
            },
            {
              "tags": [
                "x_SICK Operating Guidelines"
              ],
              "url": "https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF"
            },
            {
              "tags": [
                "x_ICS-CERT recommended practices on Industrial Security"
              ],
              "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices"
            },
            {
              "tags": [
                "x_CVSS v3.1 Calculator"
              ],
              "url": "https://www.first.org/cvss/calculator/3.1"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.pdf"
            },
            {
              "tags": [
                "vendor-advisory",
                "x_csaf"
              ],
              "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "For InspectorP61x, InspectorP62x and TiM3xx: Customers are strongly recommended to upgrade to the latest release."
                }
              ],
              "value": "For InspectorP61x, InspectorP62x and TiM3xx: Customers are strongly recommended to upgrade to the latest release."
            }
          ],
          "source": {
            "advisory": "SCA-2024-0006",
            "discovery": "EXTERNAL"
          },
          "title": "SICK InspectorP61x, SICK InspectorP62x and SICK TiM3xx are vulnerable for pass-the-hash attacks",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
        "assignerShortName": "SICK AG",
        "cveId": "CVE-2024-10773",
        "datePublished": "2024-12-06T12:31:10.776Z",
        "dateReserved": "2024-11-04T13:07:00.547Z",
        "dateUpdated": "2024-12-09T14:44:36.597Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-10772 (GCVE-0-2024-10772)

    Vulnerability from cvelistv5 – Published: 2024-12-06 12:28 – Updated: 2024-12-09 14:46
    VLAI
    Title
    SICK InspectorP61x and SICK InspectorP62x are vulnerable for firmware modification
    Summary
    Since the firmware update is not validated, an attacker can install modified firmware on the device. This has a high impact on the availabilty, integrity and confidentiality up to the complete compromise of the device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-12-09 14:44 UTC
    CWE
    • CWE-649 - Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking
    Assigner
    References
    URL Tags
    https://sick.com/psirt x_SICK PSIRT Website
    https://cdn.sick.com/media/docs/1/11/411/Special_… x_SICK Operating Guidelines
    https://www.cisa.gov/resources-tools/resources/ic… x_ICS-CERT recommended practices on Industrial Security
    https://www.first.org/cvss/calculator/3.1 x_CVSS v3.1 Calculator
    https://www.sick.com/.well-known/csaf/white/2024/… vendor-advisory
    https://www.sick.com/.well-known/csaf/white/2024/… vendor-advisoryx_csaf
    Impacted products
    Vendor Product Version
    SICK AG SICK InspectorP61x Affected: 0 , < <5.0.0 (custom)
    Create a notification for this product.
    SICK AG SICK InspectorP62x Affected: 0 , < <5.0.0 (custom)
    Create a notification for this product.
    sick inspector61x_firmware Affected: 0 , < 5.0.0 (custom)
        cpe:2.3:o:sick:inspector61x_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    sick inspector62x_firmware Affected: 0 , < 5.0.0 (custom)
        cpe:2.3:o:sick:inspector62x_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-12-06 12:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:sick:inspector61x_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "inspector61x_firmware",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThan": "5.0.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:sick:inspector62x_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "inspector62x_firmware",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThan": "5.0.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-10772",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-12-09T14:44:58.610795Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-09T14:46:03.214Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "SICK InspectorP61x",
              "vendor": "SICK AG",
              "versions": [
                {
                  "lessThan": "\u003c5.0.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "SICK InspectorP62x",
              "vendor": "SICK AG",
              "versions": [
                {
                  "lessThan": "\u003c5.0.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Manuel Stotz"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Tobias Jaeger"
            }
          ],
          "datePublic": "2024-12-06T12:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Since the firmware update is not validated, an attacker can install modified firmware on the\ndevice. This has a high impact on the availabilty, integrity and confidentiality up to the complete compromise of the device."
                }
              ],
              "value": "Since the firmware update is not validated, an attacker can install modified firmware on the\ndevice. This has a high impact on the availabilty, integrity and confidentiality up to the complete compromise of the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-649",
                  "description": "CWE-649 Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-12-06T12:28:56.564Z",
            "orgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
            "shortName": "SICK AG"
          },
          "references": [
            {
              "tags": [
                "x_SICK PSIRT Website"
              ],
              "url": "https://sick.com/psirt"
            },
            {
              "tags": [
                "x_SICK Operating Guidelines"
              ],
              "url": "https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF"
            },
            {
              "tags": [
                "x_ICS-CERT recommended practices on Industrial Security"
              ],
              "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices"
            },
            {
              "tags": [
                "x_CVSS v3.1 Calculator"
              ],
              "url": "https://www.first.org/cvss/calculator/3.1"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.pdf"
            },
            {
              "tags": [
                "vendor-advisory",
                "x_csaf"
              ],
              "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "For InspectorP61x and InspectorP62x: Customers are strongly recommended to upgrade to the latest release."
                }
              ],
              "value": "For InspectorP61x and InspectorP62x: Customers are strongly recommended to upgrade to the latest release."
            }
          ],
          "source": {
            "advisory": "SCA-2024-0006",
            "discovery": "EXTERNAL"
          },
          "title": "SICK InspectorP61x and SICK InspectorP62x are vulnerable for firmware modification",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
        "assignerShortName": "SICK AG",
        "cveId": "CVE-2024-10772",
        "datePublished": "2024-12-06T12:28:56.564Z",
        "dateReserved": "2024-11-04T13:06:59.393Z",
        "dateUpdated": "2024-12-09T14:46:03.214Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-10771 (GCVE-0-2024-10771)

    Vulnerability from cvelistv5 – Published: 2024-12-06 12:24 – Updated: 2026-05-13 12:04
    VLAI
    Title
    SICK InspectorP61x, SICK InspectorP62x and SICK TiM3xx are vulnerable for remote code execution
    Summary
    Due to missing input validation during one step of the firmware update process, the product is vulnerable to remote code execution. With network access and the user level ”Service”, an attacker can execute arbitrary system commands in the root user’s contexts.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-12-09 14:46 UTC
    CWE
    • CWE-94 - Improper Control of Generation of Code ('Code Injection')
    Assigner
    References
    URL Tags
    https://sick.com/psirt x_SICK PSIRT Website
    https://cdn.sick.com/media/docs/1/11/411/Special_… x_SICK Operating Guidelines
    https://www.cisa.gov/resources-tools/resources/ic… x_ICS-CERT recommended practices on Industrial Security
    https://www.first.org/cvss/calculator/3.1 x_CVSS v3.1 Calculator
    https://www.sick.com/.well-known/csaf/white/2024/… vendor-advisory
    https://www.sick.com/.well-known/csaf/white/2024/… vendor-advisoryx_csaf
    Impacted products
    Vendor Product Version
    SICK AG SICK InspectorP61x Affected: 0 , < <5.0.0 (custom)
    Create a notification for this product.
    SICK AG SICK InspectorP62x Affected: 0 , < <5.0.0 (custom)
    Create a notification for this product.
    SICK AG TiM3xx Affected: 0 , < <5.10.0 (custom)
    Create a notification for this product.
    SICK AG TDC-X401GL Affected: all versions
    Create a notification for this product.
    sick inspector61x_firmware Affected: 0 , < 5.0.0 (custom)
        cpe:2.3:o:sick:inspector61x_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    sick inspector62x_firmware Affected: 0 , < 5.0.0 (custom)
        cpe:2.3:o:sick:inspector62x_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    sick tim3xx Affected: 0 , < 5.10.0 (custom)
        cpe:2.3:a:sick:tim3xx:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-12-06 12:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:sick:inspector61x_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "inspector61x_firmware",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThan": "5.0.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:sick:inspector62x_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "inspector62x_firmware",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThan": "5.0.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:sick:tim3xx:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "tim3xx",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThan": "5.10.0",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-10771",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-12-09T14:46:19.943493Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-09T14:47:30.064Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "SICK InspectorP61x",
              "vendor": "SICK AG",
              "versions": [
                {
                  "lessThan": "\u003c5.0.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "SICK InspectorP62x",
              "vendor": "SICK AG",
              "versions": [
                {
                  "lessThan": "\u003c5.0.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TiM3xx",
              "vendor": "SICK AG",
              "versions": [
                {
                  "lessThan": "\u003c5.10.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "TDC-X401GL",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Manuel Stotz"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Tobias Jaeger"
            }
          ],
          "datePublic": "2024-12-06T12:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Due to missing input validation during one step of the firmware update process, the product\nis vulnerable to remote code execution. With network access and the user level \u201dService\u201d, an attacker\ncan execute arbitrary system commands in the root user\u2019s contexts."
                }
              ],
              "value": "Due to missing input validation during one step of the firmware update process, the product\nis vulnerable to remote code execution. With network access and the user level \u201dService\u201d, an attacker\ncan execute arbitrary system commands in the root user\u2019s contexts."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-94",
                  "description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-13T12:04:13.962Z",
            "orgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
            "shortName": "SICK AG"
          },
          "references": [
            {
              "tags": [
                "x_SICK PSIRT Website"
              ],
              "url": "https://sick.com/psirt"
            },
            {
              "tags": [
                "x_SICK Operating Guidelines"
              ],
              "url": "https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF"
            },
            {
              "tags": [
                "x_ICS-CERT recommended practices on Industrial Security"
              ],
              "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices"
            },
            {
              "tags": [
                "x_CVSS v3.1 Calculator"
              ],
              "url": "https://www.first.org/cvss/calculator/3.1"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.pdf"
            },
            {
              "tags": [
                "vendor-advisory",
                "x_csaf"
              ],
              "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "For InspectorP61x and InspectorP62x: Customers are strongly recommended to upgrade to the latest release."
                }
              ],
              "value": "For InspectorP61x and InspectorP62x: Customers are strongly recommended to upgrade to the latest release."
            }
          ],
          "source": {
            "advisory": "SCA-2024-0006",
            "discovery": "EXTERNAL"
          },
          "title": "SICK InspectorP61x, SICK InspectorP62x and SICK TiM3xx are vulnerable for remote code execution",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "For TiM3xx:\u0026nbsp;\n\nWe recommend updating the firmware only in a trusted environment."
                }
              ],
              "value": "For TiM3xx:\u00a0\n\nWe recommend updating the firmware only in a trusted environment."
            },
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "For\u0026nbsp;TDC-X401GL: Upon completion of the initial device setup, deactivate AppEngine. Disabling it fully mitigates\nthis vulnerability."
                }
              ],
              "value": "For\u00a0TDC-X401GL: Upon completion of the initial device setup, deactivate AppEngine. Disabling it fully mitigates\nthis vulnerability."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
        "assignerShortName": "SICK AG",
        "cveId": "CVE-2024-10771",
        "datePublished": "2024-12-06T12:24:40.610Z",
        "dateReserved": "2024-11-04T13:06:55.136Z",
        "dateUpdated": "2026-05-13T12:04:13.962Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-10025 (GCVE-0-2024-10025)

    Vulnerability from cvelistv5 – Published: 2024-10-17 09:58 – Updated: 2024-10-17 16:33
    VLAI
    Title
    Vulnerability in SICK CLV6xx, SICK Lector6xx and SICK RFx6xx
    Summary
    A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By exploiting these plaintext credentials, an attacker can log into affected SICK products as an “Authorized Client” if the customer has not changed the default password.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-17 13:41 UTC
    CWE
    • CWE-798 - Use of Hard-coded Credentials
    Assigner
    References
    URL Tags
    https://sick.com/psirt x_SICK PSIRT Webseite
    https://www.cisa.gov/resources-tools/resources/ic… x_ICS-CERT recommended practices on Industrial Security
    https://cdn.sick.com/media/docs/1/11/411/Special_… x_SICK Operating Guidelines
    https://www.first.org/cvss/calculator/3.1 x_CVSS v3.1 Calculator
    https://www.sick.com/.well-known/csaf/white/2024/… vendor-advisory
    https://www.sick.com/.well-known/csaf/white/2024/… vendor-advisoryx_csaf
    Impacted products
    Vendor Product Version
    SICK AG SICK CLV6xx Affected: all versions
    Create a notification for this product.
    SICK AG SICK Lector6xx Affected: all versions
    Create a notification for this product.
    SICK AG SICK RFx6xx Affected: all versions
    Create a notification for this product.
    sick rfu620-10507_firmware Affected: 0 , < * (custom)
        cpe:2.3:o:sick:lector611_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:sick:lector610_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:sick:lector620_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:lector621_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:lector622_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:lector630_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:lector632_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:lector640_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:lector642_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:lector650_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:lector651_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:lector654_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:clv620_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:clv621_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:clv622_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:clv630_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:clv631_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:clv632_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:clv640_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:clv642_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:clv650_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:clv651_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu610-10600_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu610-10601_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu610-10603_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu610-10604_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu610-10605_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu610-10607_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu610-10609_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu610-10610_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu610-10613_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu610-10614_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu610-10618_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu610-10700_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu620-10100_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu620-10101_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu620-10102_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu620-10103_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu620-10104_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu620-10105_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu620-10107_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu620-10108_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu620-10111_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu620-10114_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu620-10118_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu620-10400_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu620-10401_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu620-10500_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu620-10501_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu620-10503_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu620-10504_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:sick:rfu620-10507_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-10-17 09:44
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:sick:lector611_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:lector610_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:lector620_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:lector621_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:lector622_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:lector630_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:lector632_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:lector640_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:lector642_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:lector650_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:lector651_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:lector654_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:clv620_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:clv621_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:clv622_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:clv630_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:clv631_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:clv632_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:clv640_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:clv642_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:clv650_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:clv651_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu610-10600_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu610-10601_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu610-10603_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu610-10604_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu610-10605_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu610-10607_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu610-10609_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu610-10610_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu610-10613_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu610-10614_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu610-10618_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu610-10700_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu620-10100_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu620-10101_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu620-10102_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu620-10103_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu620-10104_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu620-10105_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu620-10107_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu620-10108_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu620-10111_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu620-10114_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu620-10118_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu620-10400_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu620-10401_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu620-10500_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu620-10501_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu620-10503_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu620-10504_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:sick:rfu620-10507_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "rfu620-10507_firmware",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-10025",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-17T13:41:03.974704Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-17T16:33:53.645Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "SICK CLV6xx",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "SICK Lector6xx",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "SICK RFx6xx",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            }
          ],
          "datePublic": "2024-10-17T09:44:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By exploiting these plaintext credentials, an attacker can log into affected SICK products as an \u201cAuthorized Client\u201d if the customer has not changed the default password."
                }
              ],
              "value": "A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By exploiting these plaintext credentials, an attacker can log into affected SICK products as an \u201cAuthorized Client\u201d if the customer has not changed the default password."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.1,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-798",
                  "description": "CWE-798 Use of Hard-coded Credentials",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-17T09:58:03.111Z",
            "orgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
            "shortName": "SICK AG"
          },
          "references": [
            {
              "tags": [
                "x_SICK PSIRT Webseite"
              ],
              "url": "https://sick.com/psirt"
            },
            {
              "tags": [
                "x_ICS-CERT recommended practices on Industrial Security"
              ],
              "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices"
            },
            {
              "tags": [
                "x_SICK Operating Guidelines"
              ],
              "url": "https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF"
            },
            {
              "tags": [
                "x_CVSS v3.1 Calculator"
              ],
              "url": "https://www.first.org/cvss/calculator/3.1"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0003.pdf"
            },
            {
              "tags": [
                "vendor-advisory",
                "x_csaf"
              ],
              "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0003.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Customers are strongly advised to change their default passwords.\u003cbr\u003e"
                }
              ],
              "value": "Customers are strongly advised to change their default passwords."
            }
          ],
          "source": {
            "advisory": "sca-2024-0003",
            "discovery": "INTERNAL"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2024-10-17T09:53:00.000Z",
              "value": "1: Initial version"
            }
          ],
          "title": "Vulnerability in SICK CLV6xx, SICK Lector6xx and SICK RFx6xx",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
        "assignerShortName": "SICK AG",
        "cveId": "CVE-2024-10025",
        "datePublished": "2024-10-17T09:58:03.111Z",
        "dateReserved": "2024-10-16T07:45:23.632Z",
        "dateUpdated": "2024-10-17T16:33:53.645Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-8751 (GCVE-0-2024-8751)

    Vulnerability from cvelistv5 – Published: 2024-09-12 21:38 – Updated: 2026-07-24 12:01
    VLAI
    Title
    CVE-2024-8751
    Summary
    A vulnerability allows a remote unauthenticated attacker to modify the prod uct’s IP address over the Sopas ET interface. This can lead to a Denial of Service attack.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-13 13:53 UTC
    CWE
    • CWE-306 - Missing Authentication for Critical Function
    Assigner
    Impacted products
    Vendor Product Version
    SICK AG MSC800 Affected: V1.0 , ≤ <=V4.25 (custom)
    Affected: S1.0 , ≤ <=S2.93.19 (custom)
    Create a notification for this product.
    Endress+Hauser MARSIC200 Affected: all versions (custom)
    Create a notification for this product.
    Endress+Hauser MARSIC280 Affected: all versions (custom)
    Create a notification for this product.
    Endress+Hauser MARSIC300 Affected: all versions (custom)
    Create a notification for this product.
    Endress+Hauser MCS100FT Affected: all versions (custom)
    Create a notification for this product.
    Endress+Hauser MCS200HW Affected: all versions (custom)
    Create a notification for this product.
    Endress+Hauser MCS300P Affected: all versions (custom)
    Create a notification for this product.
    Endress+Hauser MERCEM300Z Affected: all versions (custom)
    Create a notification for this product.
    Endress+Hauser SAM800 Affected: all versions (custom)
    Create a notification for this product.
    Endress+Hauser SIPROCESS Affected: all versions (custom)
    Create a notification for this product.
    Endress+Hauser GMS800 Affected: all versions (custom)
    Create a notification for this product.
    Endress+Hauser GMS800 FIDOR Affected: all versions (custom)
    Create a notification for this product.
    Endress+Hauser GM32 Affected: all versions (custom)
    Create a notification for this product.
    Endress+Hauser VICOTEC320 Affected: all versions (custom)
    Create a notification for this product.
    Endress+Hauser MCU ETH-Service and Modbus-TCP Module Affected: all versions (custom)
    Create a notification for this product.
    Endress+Hauser FLPS Affected: all versions (custom)
    Create a notification for this product.
    Endress+Hauser MES1B B&B Converter Affected: all versions (custom)
    Create a notification for this product.
    sick msc800_firmware Affected: 1.0 , ≤ 4.25 (custom)
    Affected: 1.0 , ≤ s2.93.19 (custom)
        cpe:2.3:o:sick:msc800_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-09-12 21:33
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:sick:msc800_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "msc800_firmware",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThanOrEqual": "4.25",
                    "status": "affected",
                    "version": "1.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "s2.93.19",
                    "status": "affected",
                    "version": "1.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-8751",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-13T13:53:13.856056Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-13T14:02:19.375Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "MSC800",
              "vendor": "SICK AG",
              "versions": [
                {
                  "lessThanOrEqual": "\u003c=V4.25",
                  "status": "affected",
                  "version": "V1.0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "\u003c=S2.93.19",
                  "status": "affected",
                  "version": "S1.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "MARSIC200",
              "vendor": "Endress+Hauser",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "MARSIC280",
              "vendor": "Endress+Hauser",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "MARSIC300",
              "vendor": "Endress+Hauser",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "MCS100FT",
              "vendor": "Endress+Hauser",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "MCS200HW",
              "vendor": "Endress+Hauser",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "MCS300P",
              "vendor": "Endress+Hauser",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "MERCEM300Z",
              "vendor": "Endress+Hauser",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "SAM800",
              "vendor": "Endress+Hauser",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "SIPROCESS",
              "vendor": "Endress+Hauser",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "GMS800",
              "vendor": "Endress+Hauser",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "GMS800 FIDOR",
              "vendor": "Endress+Hauser",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "GM32",
              "vendor": "Endress+Hauser",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "VICOTEC320",
              "vendor": "Endress+Hauser",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "MCU ETH-Service and Modbus-TCP Module",
              "vendor": "Endress+Hauser",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "FLPS",
              "vendor": "Endress+Hauser",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "MES1B B\u0026B Converter",
              "vendor": "Endress+Hauser",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2024-09-12T21:33:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A vulnerability allows a remote unauthenticated attacker to modify the prod\nuct\u2019s IP address over the Sopas ET interface. This can lead to a Denial of Service attack.\u0026nbsp;\u003cbr\u003e"
                }
              ],
              "value": "A vulnerability allows a remote unauthenticated attacker to modify the prod\nuct\u2019s IP address over the Sopas ET interface. This can lead to a Denial of Service attack."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306 Missing Authentication for Critical Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-24T12:01:28.194Z",
            "orgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
            "shortName": "SICK AG"
          },
          "references": [
            {
              "tags": [
                "x_SICK PSIRT Website"
              ],
              "url": "https://sick.com/psirt"
            },
            {
              "tags": [
                "x_SICK Operating Guidelines"
              ],
              "url": "https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF"
            },
            {
              "tags": [
                "x_ICS-CERT recommended practices on Industrial Security"
              ],
              "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices"
            },
            {
              "tags": [
                "x_CVSS v3.1 Calculator"
              ],
              "url": "https://www.first.org/cvss/calculator/3.1"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0002.pdf"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0009.pdf"
            },
            {
              "tags": [
                "x_The canonical URL"
              ],
              "url": "https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0002.json"
            },
            {
              "tags": [
                "x_The canonical URL"
              ],
              "url": "https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0009.json"
            },
            {
              "tags": [
                "x_Endress+Hauser"
              ],
              "url": "https://www.endress.com"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "For Endress+Hauser MSC800FT: Customers who use the version \u0026lt;=V4.25 are strongly recommended to upgrade to the latest\nrelease V4.26\n\n\u003cbr\u003e"
                }
              ],
              "value": "For Endress+Hauser MSC800FT: Customers who use the version \u003c=V4.25 are strongly recommended to upgrade to the latest\nrelease V4.26"
            },
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "For Endress+Hauser MSC800FT: Customers who use the version \u0026lt;=S2.93.19 are strongly recommended to upgrade to the\nlatest release S2.93.20.\n\n\u003cbr\u003e"
                }
              ],
              "value": "For Endress+Hauser MSC800FT: Customers who use the version \u003c=S2.93.19 are strongly recommended to upgrade to the\nlatest release S2.93.20."
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2024-09-12T21:36:00.000Z",
              "value": "1: Initial version"
            },
            {
              "lang": "en",
              "time": "2026-07-16T10:00:00.000Z",
              "value": "2: Added more products"
            }
          ],
          "title": "CVE-2024-8751",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eFor Endress+Hauser\u0026nbsp;MARSIC200, MARSIC280, MARSIC300, MCS100FT, MCS200HW, MCS300P, MERCEM300Z, SAM800, SIPROCESS, GMS800, GMS800 FIDOR, GM32, VICOTEC320, MCU ETH-Service and Modbus-TCP Module, FLPS, MES1B B\u0026amp;B Converter:\u0026nbsp; Please make sure that only trusted entities have access to the device. Furthermore, you should apply the following General Security Measures when operating the product to mitigate the associated security risk. The \u201dICS-CERT recommended practices on Industrial Security\u201d could help to implement the general security practices.\u003c/p\u003e"
                }
              ],
              "value": "For Endress+Hauser\u00a0MARSIC200, MARSIC280, MARSIC300, MCS100FT, MCS200HW, MCS300P, MERCEM300Z, SAM800, SIPROCESS, GMS800, GMS800 FIDOR, GM32, VICOTEC320, MCU ETH-Service and Modbus-TCP Module, FLPS, MES1B B\u0026B Converter:\u00a0 Please make sure that only trusted entities have access to the device. Furthermore, you should apply the following General Security Measures when operating the product to mitigate the associated security risk. The \u201dICS-CERT recommended practices on Industrial Security\u201d could help to implement the general security practices."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
        "assignerShortName": "SICK AG",
        "cveId": "CVE-2024-8751",
        "datePublished": "2024-09-12T21:38:37.516Z",
        "dateReserved": "2024-09-12T13:17:03.176Z",
        "dateUpdated": "2026-07-24T12:01:28.194Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2023-5246 (GCVE-0-2023-5246)

    Vulnerability from cvelistv5 – Published: 2023-10-23 12:22 – Updated: 2026-06-01 12:17
    VLAI
    Summary
    Authentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073, 1127717, 1130282, 1044074, 1121597, 1099832, 1051432, 1127487, 1069070, 1112296, 1044072, 1121596, 1099830 allows an unauthenticated remote attacker to potentially impact the availability, integrity and confidentiality of the gateways via an authentication bypass by capture-replay.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-11 15:28 UTC
    CWE
    • Authentication Bypass by Capture-replay
    Assigner
    Impacted products
    Vendor Product Version
    SICK AG FX0-GMOD00000 Affected: vers:all/*
    Create a notification for this product.
    SICK AG FX0-GMOD00010 Affected: vers:all/*
    Create a notification for this product.
    SICK AG FX0-GMOD00030 Affected: vers:all/*
    Create a notification for this product.
    SICK AG FX0-GPNT00000 Affected: vers:all/*
    Create a notification for this product.
    SICK AG FX0-GPNT00010 Affected: vers:all/*
    Create a notification for this product.
    SICK AG FX0-GPNT00030 Affected: vers:all/*
    Create a notification for this product.
    SICK AG FX0-GETC00000 Affected: vers:all/*
    Create a notification for this product.
    SICK AG FX0-GETC00010 Affected: vers:all/*
    Create a notification for this product.
    SICK AG FX3-GEPR00000 Affected: vers:all/*
    Create a notification for this product.
    SICK AG FX3-GEPR00010 Affected: vers:all/*
    Create a notification for this product.
    SICK AG FX0-GENT00000 Affected: vers:all/*
    Create a notification for this product.
    SICK AG FX0-GENT00010 Affected: vers:all/*
    Create a notification for this product.
    SICK AG FX0-GENT00030 Affected: vers:all/*
    Create a notification for this product.
    sick fx0-gmod00000_firmware Affected: 0 , ≤ * (custom)
        cpe:2.3:o:sick:fx0-gmod00000_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    sick fx0-gmod00010_firmware Affected: 0 , ≤ * (custom)
        cpe:2.3:o:sick:fx0-gmod00010_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    sick fx0-gmod00030_firmware Affected: 0 , ≤ * (custom)
        cpe:2.3:o:sick:fx0-gmod00030_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    sick fx0-gpnt00000_firmware Affected: 0 , ≤ * (custom)
        cpe:2.3:o:sick:fx0-gpnt00000_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    sick fx0-gpnt00010_firmware Affected: 0 , ≤ * (custom)
        cpe:2.3:o:sick:fx0-gpnt00010_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    sick fx0-gpnt00030_firmware Affected: 0 , ≤ * (custom)
        cpe:2.3:o:sick:fx0-gpnt00030_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    sick fx0-getc00000 Affected: 0 , ≤ * (custom)
        cpe:2.3:o:sick:fx0-getc00000:*:*:*:*:*:*:*:*
    Create a notification for this product.
    sick fx0-getc00010 Affected: 0 , ≤ * (custom)
        cpe:2.3:o:sick:fx0-getc00010:*:*:*:*:*:*:*:*
    Create a notification for this product.
    sick fx3-gepr00000 Affected: 0 , ≤ * (custom)
        cpe:2.3:o:sick:fx3-gepr00000:*:*:*:*:*:*:*:*
    Create a notification for this product.
    sick fx3-gepr00010 Affected: 0 , ≤ * (custom)
        cpe:2.3:o:sick:fx3-gepr00010:*:*:*:*:*:*:*:*
    Create a notification for this product.
    sick fx0-gent00000_firmware Affected: 0 , ≤ * (custom)
        cpe:2.3:o:sick:fx0-gent00000_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    sick fx0-gent00010_firmware Affected: 0 , ≤ * (custom)
        cpe:2.3:o:sick:fx0-gent00010_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    sick fx0-gent00030_firmware Affected: 0 , ≤ * (custom)
        cpe:2.3:o:sick:fx0-gent00030_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T07:52:08.511Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "issue-tracking",
                  "x_transferred"
                ],
                "url": "https://sick.com/psirt"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0011.pdf"
              },
              {
                "tags": [
                  "x_csaf",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0011.json"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:sick:fx0-gmod00000_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fx0-gmod00000_firmware",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:sick:fx0-gmod00010_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fx0-gmod00010_firmware",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:sick:fx0-gmod00030_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fx0-gmod00030_firmware",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:sick:fx0-gpnt00000_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fx0-gpnt00000_firmware",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:sick:fx0-gpnt00010_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fx0-gpnt00010_firmware",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:sick:fx0-gpnt00030_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fx0-gpnt00030_firmware",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:sick:fx0-getc00000:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fx0-getc00000",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:sick:fx0-getc00010:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fx0-getc00010",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:sick:fx3-gepr00000:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fx3-gepr00000",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:sick:fx3-gepr00010:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fx3-gepr00010",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:sick:fx0-gent00000_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fx0-gent00000_firmware",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:sick:fx0-gent00010_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fx0-gent00010_firmware",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:sick:fx0-gent00030_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fx0-gent00030_firmware",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-5246",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-11T15:28:47.832868Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-11T16:17:17.559Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "FX0-GMOD00000",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "vers:all/*"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "FX0-GMOD00010",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "vers:all/*"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "FX0-GMOD00030",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "vers:all/*"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "FX0-GPNT00000",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "vers:all/*"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "FX0-GPNT00010",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "vers:all/*"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "FX0-GPNT00030",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "vers:all/*"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "FX0-GETC00000",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "vers:all/*"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "FX0-GETC00010",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "vers:all/*"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "FX3-GEPR00000",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "vers:all/*"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "FX3-GEPR00010",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "vers:all/*"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "FX0-GENT00000",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "vers:all/*"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "FX0-GENT00010",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "vers:all/*"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "FX0-GENT00030",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "vers:all/*"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Authentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073, 1127717, 1130282, 1044074, 1121597, 1099832, 1051432, 1127487, 1069070, 1112296, 1044072, 1121596, 1099830 allows an unauthenticated remote attacker to potentially impact the availability, integrity and confidentiality of the gateways via an authentication bypass by capture-replay."
                }
              ],
              "value": "Authentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073, 1127717, 1130282, 1044074, 1121597, 1099832, 1051432, 1127487, 1069070, 1112296, 1044072, 1121596, 1099830 allows an unauthenticated remote attacker to potentially impact the availability, integrity and confidentiality of the gateways via an authentication bypass by capture-replay."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Authentication Bypass by Capture-replay",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-01T12:17:37.314Z",
            "orgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
            "shortName": "SICK AG"
          },
          "references": [
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://sick.com/psirt"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0011.pdf"
            },
            {
              "tags": [
                "x_csaf"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0011.json"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Please make sure that you apply general security practices when operating the SICK Flexi Soft Gateways. The following General Security Practices and Operating Guidelines could mitigate the associated security risk."
                }
              ],
              "value": "Please make sure that you apply general security practices when operating the SICK Flexi Soft Gateways. The following General Security Practices and Operating Guidelines could mitigate the associated security risk."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
        "assignerShortName": "SICK AG",
        "cveId": "CVE-2023-5246",
        "datePublished": "2023-10-23T12:22:19.895Z",
        "dateReserved": "2023-09-28T06:29:07.044Z",
        "dateUpdated": "2026-06-01T12:17:37.314Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2023-5102 (GCVE-0-2023-5102)

    Vulnerability from cvelistv5 – Published: 2023-10-09 12:09 – Updated: 2024-12-09 13:55
    VLAI
    Summary
    Insufficient Control Flow Management in RDT400 in SICK APU allows an unprivileged remote attacker to potentially enable hidden functionality via HTTP requests.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-19 14:44 UTC
    CWE
    • CWE-691 - Insufficient Control Flow Management
    Assigner
    Impacted products
    Vendor Product Version
    SICK AG APU0200 Affected: all versions
    Create a notification for this product.
    sick apu0200 Affected: 0 , < * (custom)
        cpe:2.3:h:sick:apu0200:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T07:44:53.761Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "issue-tracking",
                  "x_transferred"
                ],
                "url": "https://sick.com/psirt"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.pdf"
              },
              {
                "tags": [
                  "x_csaf",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.json"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:sick:apu0200:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "apu0200",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-5102",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-19T14:44:22.301997Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-09T13:55:52.981Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "APU0200",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\nInsufficient Control Flow Management in RDT400 in SICK APU allows an unprivileged remote attacker to potentially enable hidden functionality via HTTP requests.\n\n\n"
                }
              ],
              "value": "\nInsufficient Control Flow Management in RDT400 in SICK APU allows an unprivileged remote attacker to potentially enable hidden functionality via HTTP requests.\n\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-691",
                  "description": "CWE-691 Insufficient Control Flow Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-09T12:09:08.155Z",
            "orgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
            "shortName": "SICK AG"
          },
          "references": [
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://sick.com/psirt"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.pdf"
            },
            {
              "tags": [
                "x_csaf"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\n\nThe recommended solution is to update the image to a version \u0026gt;= 4.0.0.6 as soon as possible.\u003cbr\u003e"
                }
              ],
              "value": "\n\n\nThe recommended solution is to update the image to a version \u003e= 4.0.0.6 as soon as possible.\n"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
        "assignerShortName": "SICK AG",
        "cveId": "CVE-2023-5102",
        "datePublished": "2023-10-09T12:09:08.155Z",
        "dateReserved": "2023-09-21T07:10:38.363Z",
        "dateUpdated": "2024-12-09T13:55:52.981Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-5101 (GCVE-0-2023-5101)

    Vulnerability from cvelistv5 – Published: 2023-10-09 12:07 – Updated: 2024-12-09 13:55
    VLAI
    Summary
    Files or Directories Accessible to External Parties in RDT400 in SICK APU allows an unprivileged remote attacker to download various files from the server via HTTP requests.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-19 14:47 UTC
    CWE
    • CWE-552 - Files or Directories Accessible to External Parties
    Assigner
    Impacted products
    Vendor Product Version
    SICK AG APU0200 Affected: all versions
    Create a notification for this product.
    sick apu0200 Affected: 0 , < * (custom)
        cpe:2.3:h:sick:apu0200:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T07:44:53.728Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "issue-tracking",
                  "x_transferred"
                ],
                "url": "https://sick.com/psirt"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.pdf"
              },
              {
                "tags": [
                  "x_csaf",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.json"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:sick:apu0200:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "apu0200",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-5101",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-19T14:47:19.122992Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-09T13:55:57.571Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "APU0200",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\nFiles or Directories Accessible to External Parties in RDT400 in SICK APU allows an\nunprivileged remote attacker to download various files from the server via HTTP requests.\n\n"
                }
              ],
              "value": "\nFiles or Directories Accessible to External Parties in RDT400 in SICK APU allows an\nunprivileged remote attacker to download various files from the server via HTTP requests.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-552",
                  "description": "CWE-552 Files or Directories Accessible to External Parties",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-09T12:07:13.545Z",
            "orgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
            "shortName": "SICK AG"
          },
          "references": [
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://sick.com/psirt"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.pdf"
            },
            {
              "tags": [
                "x_csaf"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\n\nThe recommended solution is to update the image to a version \u0026gt;= 4.0.0.6 as soon as possible.\u003cbr\u003e"
                }
              ],
              "value": "\n\n\nThe recommended solution is to update the image to a version \u003e= 4.0.0.6 as soon as possible.\n"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
        "assignerShortName": "SICK AG",
        "cveId": "CVE-2023-5101",
        "datePublished": "2023-10-09T12:07:13.545Z",
        "dateReserved": "2023-09-21T07:10:37.521Z",
        "dateUpdated": "2024-12-09T13:55:57.571Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-43697 (GCVE-0-2023-43697)

    Vulnerability from cvelistv5 – Published: 2023-10-09 12:03 – Updated: 2024-12-09 13:54
    VLAI
    Summary
    Modification of Assumed-Immutable Data (MAID) in RDT400 in SICK APU allows an unprivileged remote attacker to make the site unable to load necessary strings via changing file paths using HTTP requests.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-19 14:53 UTC
    CWE
    • CWE-471 - Modification of Assumed-Immutable Data (MAID)
    Assigner
    Impacted products
    Vendor Product Version
    SICK AG APU0200 Affected: all versions
    Create a notification for this product.
    sick apu0200 Affected: 0 , < * (custom)
        cpe:2.3:h:sick:apu0200:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T19:44:44.094Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "issue-tracking",
                  "x_transferred"
                ],
                "url": "https://sick.com/psirt"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.pdf"
              },
              {
                "tags": [
                  "x_csaf",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.json"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:sick:apu0200:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "apu0200",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-43697",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-19T14:53:10.361349Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-09T13:54:12.933Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "APU0200",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\nModification of Assumed-Immutable Data (MAID) in RDT400 in SICK APU allows an\nunprivileged remote attacker to make the site unable to load necessary strings via changing file paths\nusing HTTP requests.\n\n"
                }
              ],
              "value": "\nModification of Assumed-Immutable Data (MAID) in RDT400 in SICK APU allows an\nunprivileged remote attacker to make the site unable to load necessary strings via changing file paths\nusing HTTP requests.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-471",
                  "description": "CWE-471 Modification of Assumed-Immutable Data (MAID)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-09T12:03:27.736Z",
            "orgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
            "shortName": "SICK AG"
          },
          "references": [
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://sick.com/psirt"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.pdf"
            },
            {
              "tags": [
                "x_csaf"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\n\nThe recommended solution is to update the image to a version \u0026gt;= 4.0.0.6 as soon as possible.\u003cbr\u003e"
                }
              ],
              "value": "\n\n\nThe recommended solution is to update the image to a version \u003e= 4.0.0.6 as soon as possible.\n"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
        "assignerShortName": "SICK AG",
        "cveId": "CVE-2023-43697",
        "datePublished": "2023-10-09T12:03:27.736Z",
        "dateReserved": "2023-09-21T07:10:31.289Z",
        "dateUpdated": "2024-12-09T13:54:12.933Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-43699 (GCVE-0-2023-43699)

    Vulnerability from cvelistv5 – Published: 2023-10-09 11:59 – Updated: 2024-12-09 13:54
    VLAI
    Summary
    Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU allows an unprivileged remote attacker to guess the password via trial-and-error as the login attempts are not limited.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-19 14:14 UTC
    CWE
    • CWE-307 - Improper Restriction of Excessive Authentication Attempts
    Assigner
    Impacted products
    Vendor Product Version
    SICK AG APU0200 Affected: all versions
    Create a notification for this product.
    sick apu0200 Affected: 0 , ≤ * (custom)
        cpe:2.3:h:sick:apu0200:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T19:44:43.837Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "issue-tracking",
                  "x_transferred"
                ],
                "url": "https://sick.com/psirt"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.pdf"
              },
              {
                "tags": [
                  "x_csaf",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.json"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:sick:apu0200:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "apu0200",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-43699",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-19T14:14:03.951785Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-09T13:54:43.591Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "APU0200",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\nImproper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU\nallows an unprivileged remote attacker to guess the password via trial-and-error as the login attempts\nare not limited.\n\n"
                }
              ],
              "value": "\nImproper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU\nallows an unprivileged remote attacker to guess the password via trial-and-error as the login attempts\nare not limited.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-307",
                  "description": "CWE-307 Improper Restriction of Excessive Authentication Attempts",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-09T11:59:19.748Z",
            "orgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
            "shortName": "SICK AG"
          },
          "references": [
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://sick.com/psirt"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.pdf"
            },
            {
              "tags": [
                "x_csaf"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\n\nThe recommended solution is to update the image to a version \u0026gt;= 4.0.0.6 as soon as possible.\u003cbr\u003e"
                }
              ],
              "value": "\n\n\nThe recommended solution is to update the image to a version \u003e= 4.0.0.6 as soon as possible.\n"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
        "assignerShortName": "SICK AG",
        "cveId": "CVE-2023-43699",
        "datePublished": "2023-10-09T11:59:19.748Z",
        "dateReserved": "2023-09-21T07:10:31.289Z",
        "dateUpdated": "2024-12-09T13:54:43.591Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-43700 (GCVE-0-2023-43700)

    Vulnerability from cvelistv5 – Published: 2023-10-09 11:56 – Updated: 2024-09-19 14:24
    VLAI
    Summary
    Missing Authorization in RDT400 in SICK APU allows an unprivileged remote attacker to modify data via HTTP requests that no not require authentication.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-19 14:18 UTC
    CWE
    Assigner
    Impacted products
    Vendor Product Version
    SICK AG APU0200 Affected: all versions
    Create a notification for this product.
    sick rdt400 Affected: 0 , ≤ * (custom)
        cpe:2.3:a:sick:rdt400:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T19:44:43.940Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "issue-tracking",
                  "x_transferred"
                ],
                "url": "https://sick.com/psirt"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.pdf"
              },
              {
                "tags": [
                  "x_csaf",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.json"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:sick:rdt400:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "rdt400",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-43700",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-19T14:18:26.463036Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-19T14:24:13.788Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "APU0200",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Missing Authorization in RDT400 in SICK APU allows an unprivileged remote attacker to modify data via HTTP requests that no not require authentication.\n\n"
                }
              ],
              "value": "Missing Authorization in RDT400 in SICK APU allows an unprivileged remote attacker to modify data via HTTP requests that no not require authentication.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.7,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-09T11:56:42.077Z",
            "orgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
            "shortName": "SICK AG"
          },
          "references": [
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://sick.com/psirt"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.pdf"
            },
            {
              "tags": [
                "x_csaf"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\n\n\nThe recommended solution is to update the image to a version \u0026gt;= 4.0.0.6 as soon as possible.\u003cbr\u003e"
                }
              ],
              "value": "\n\n\nThe recommended solution is to update the image to a version \u003e= 4.0.0.6 as soon as possible.\n"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
        "assignerShortName": "SICK AG",
        "cveId": "CVE-2023-43700",
        "datePublished": "2023-10-09T11:56:42.077Z",
        "dateReserved": "2023-09-21T07:10:31.289Z",
        "dateUpdated": "2024-09-19T14:24:13.788Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-43696 (GCVE-0-2023-43696)

    Vulnerability from cvelistv5 – Published: 2023-10-09 11:51 – Updated: 2024-09-18 19:37
    VLAI
    Summary
    Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous access to the FTP server.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-18 19:30 UTC
    CWE
    • CWE-284 - Improper Access Control
    Assigner
    Impacted products
    Vendor Product Version
    SICK AG APU0200 Affected: all versions
    Create a notification for this product.
    sick apu0200_firmware Affected: 0 , < 4.0.0.6 (custom)
        cpe:2.3:o:sick:apu0200_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T19:44:44.112Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "issue-tracking",
                  "x_transferred"
                ],
                "url": "https://sick.com/psirt"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.pdf"
              },
              {
                "tags": [
                  "x_csaf",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.json"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:sick:apu0200_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "affected",
                "product": "apu0200_firmware",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThan": "4.0.0.6",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-43696",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-18T19:30:55.399607Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-18T19:37:28.032Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "APU0200",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\nImproper Access Control in SICK APU allows an unprivileged remote attacker to\ndownload as well as upload arbitrary files via anonymous access to the FTP server.\n\n"
                }
              ],
              "value": "\nImproper Access Control in SICK APU allows an unprivileged remote attacker to\ndownload as well as upload arbitrary files via anonymous access to the FTP server.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "CWE-284 Improper Access Control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-10-09T11:51:45.921Z",
            "orgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
            "shortName": "SICK AG"
          },
          "references": [
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://sick.com/psirt"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.pdf"
            },
            {
              "tags": [
                "x_csaf"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\nThe recommended solution is to update the image to a version \u0026gt;= 4.0.0.6 as soon as possible.\n\n\u003cbr\u003e"
                }
              ],
              "value": "\nThe recommended solution is to update the image to a version \u003e= 4.0.0.6 as soon as possible.\n\n\n"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
        "assignerShortName": "SICK AG",
        "cveId": "CVE-2023-43696",
        "datePublished": "2023-10-09T11:51:45.921Z",
        "dateReserved": "2023-09-21T07:10:31.288Z",
        "dateUpdated": "2024-09-18T19:37:28.032Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-5288 (GCVE-0-2023-5288)

    Vulnerability from cvelistv5 – Published: 2023-09-29 11:37 – Updated: 2024-12-09 14:08
    VLAI
    Summary
    A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings. The adversary may also reset the SIM and in the worst case upload a new firmware version to the device.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-23 17:15 UTC
    CWE
    • CWE-284 - Improper Access Control
    Assigner
    Impacted products
    Vendor Product Version
    SICK AG SIM1012 Affected: all versions
    Create a notification for this product.
    sick sim1012 Affected: 0 , < * (custom)
        cpe:2.3:h:sick:sim1012:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T07:52:08.562Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "issue-tracking",
                  "x_transferred"
                ],
                "url": "https://sick.com/psirt"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0008.pdf"
              },
              {
                "tags": [
                  "x_csaf",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0008.json"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:sick:sim1012:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "sim1012",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-5288",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-23T17:15:11.997557Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-09T14:08:49.408Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "SIM1012",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\nA remote unauthorized attacker may connect to the SIM1012, interact with the device and\nchange configuration settings. The adversary may also reset the SIM and in the worst case upload a\nnew firmware version to the device.\n\n"
                }
              ],
              "value": "\nA remote unauthorized attacker may connect to the SIM1012, interact with the device and\nchange configuration settings. The adversary may also reset the SIM and in the worst case upload a\nnew firmware version to the device.\n\n"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "CWE-284 Improper Access Control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-09-29T11:37:56.571Z",
            "orgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
            "shortName": "SICK AG"
          },
          "references": [
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://sick.com/psirt"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0008.pdf"
            },
            {
              "tags": [
                "x_csaf"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0008.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\n\nSICK recommends to disable port 2111 \u0026amp; 2122 once the SIM1012 is put into operation. The\ninformation how to disable the port can be retrieved from the SIM1012 API documentation. SICK\nrecommends using the SICK AppManager in version \u0026gt;=1.5.6 for the commissioning of the SIM1012.\n\n\n\u003cbr\u003e"
                }
              ],
              "value": "\nSICK recommends to disable port 2111 \u0026 2122 once the SIM1012 is put into operation. The\ninformation how to disable the port can be retrieved from the SIM1012 API documentation. SICK\nrecommends using the SICK AppManager in version \u003e=1.5.6 for the commissioning of the SIM1012.\n\n\n\n"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
        "assignerShortName": "SICK AG",
        "cveId": "CVE-2023-5288",
        "datePublished": "2023-09-29T11:37:56.571Z",
        "dateReserved": "2023-09-29T10:17:33.150Z",
        "dateUpdated": "2024-12-09T14:08:49.408Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-31412 (GCVE-0-2023-31412)

    Vulnerability from cvelistv5 – Published: 2023-08-24 18:15 – Updated: 2026-06-01 07:29
    VLAI
    Summary
    The LMS5xx uses weak hash generation methods, resulting in the creation of insecure hashs. If an attacker manages to retrieve the hash, it could lead to collision attacks and the potential retrieval of the password.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-02 19:15 UTC
    CWE
    • Use of Weak Hash
    Assigner
    Impacted products
    Vendor Product Version
    SICK AG LMS5xx Affected: all firmware versions
    Create a notification for this product.
    sick lms5xx Affected: 0 , < * (custom)
        cpe:2.3:h:sick:lms5xx:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T14:53:30.758Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "issue-tracking",
                  "x_transferred"
                ],
                "url": "https://sick.com/psirt"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0007.pdf"
              },
              {
                "tags": [
                  "x_csaf",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0007.json"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:sick:lms5xx:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "lms5xx",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-31412",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-02T19:15:26.979357Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-09T14:12:04.011Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "LMS5xx",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "all firmware versions"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The LMS5xx uses weak hash generation methods, resulting in the creation of insecure hashs. If an attacker manages to retrieve the hash, it could lead to collision attacks and the potential retrieval of the password."
                }
              ],
              "value": "The LMS5xx uses weak hash generation methods, resulting in the creation of insecure hashs. If an attacker manages to retrieve the hash, it could lead to collision attacks and the potential retrieval of the password."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Use of Weak Hash",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-01T07:29:07.317Z",
            "orgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
            "shortName": "SICK AG"
          },
          "references": [
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://sick.com/psirt"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0007.pdf"
            },
            {
              "tags": [
                "x_csaf"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0007.json"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Please make sure that you apply general security practices when operating the LMS5xx. The following General Security Practices and Operating Guidelines could mitigate the associated security risk. It is also recommended to apply the security practices listed in the LMS5xx hardening guide."
                }
              ],
              "value": "Please make sure that you apply general security practices when operating the LMS5xx. The following General Security Practices and Operating Guidelines could mitigate the associated security risk. It is also recommended to apply the security practices listed in the LMS5xx hardening guide."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
        "assignerShortName": "SICK AG",
        "cveId": "CVE-2023-31412",
        "datePublished": "2023-08-24T18:15:53.835Z",
        "dateReserved": "2023-04-27T18:35:47.418Z",
        "dateUpdated": "2026-06-01T07:29:07.317Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2023-4420 (GCVE-0-2023-4420)

    Vulnerability from cvelistv5 – Published: 2023-08-24 18:11 – Updated: 2026-06-01 12:15
    VLAI
    Summary
    A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK LMS5xx. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive information. The attacker can exploit this weakness to eavesdrop on the communication between the LMS5xx and the Client, and potentially manipulate the data being transmitted.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-02 19:59 UTC
    CWE
    • Cleartext Transmission of Sensitive Information
    Assigner
    Impacted products
    Vendor Product Version
    SICK AG LMS5xx Affected: all firmware versions
    Create a notification for this product.
    sick lms5xx Affected: 0 , < * (custom)
        cpe:2.3:h:sick:lms5xx:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T07:24:04.690Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "issue-tracking",
                  "x_transferred"
                ],
                "url": "https://sick.com/psirt"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0007.pdf"
              },
              {
                "tags": [
                  "x_csaf",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0007.json"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:sick:lms5xx:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "lms5xx",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-4420",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-02T19:59:02.293154Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-09T14:12:37.134Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "LMS5xx",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "all firmware versions"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK LMS5xx. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive information. The attacker can exploit this weakness to eavesdrop on the communication between the LMS5xx and the Client, and potentially manipulate the data being transmitted."
                }
              ],
              "value": "A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK LMS5xx. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive information. The attacker can exploit this weakness to eavesdrop on the communication between the LMS5xx and the Client, and potentially manipulate the data being transmitted."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Cleartext Transmission of Sensitive Information",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-01T12:15:31.055Z",
            "orgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
            "shortName": "SICK AG"
          },
          "references": [
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://sick.com/psirt"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0007.pdf"
            },
            {
              "tags": [
                "x_csaf"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0007.json"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Please make sure that you apply general security practices when operating the LMS5xx. The\nfollowing General Security Practices and Operating Guidelines could mitigate the associated security\nrisk. It is also recommended to apply the security practices listed in the LMS5xx hardening guide.\n\n\u003cbr\u003e"
                }
              ],
              "value": "Please make sure that you apply general security practices when operating the LMS5xx. The\nfollowing General Security Practices and Operating Guidelines could mitigate the associated security\nrisk. It is also recommended to apply the security practices listed in the LMS5xx hardening guide."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
        "assignerShortName": "SICK AG",
        "cveId": "CVE-2023-4420",
        "datePublished": "2023-08-24T18:11:39.312Z",
        "dateReserved": "2023-08-18T13:09:48.275Z",
        "dateUpdated": "2026-06-01T12:15:31.055Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2023-4419 (GCVE-0-2023-4419)

    Vulnerability from cvelistv5 – Published: 2023-08-24 18:08 – Updated: 2026-06-01 12:14
    VLAI
    Summary
    The LMS5xx uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure settings and /or disrupt the functionality of the device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-02 19:46 UTC
    CWE
    • Use of Hard-coded Credentials
    Assigner
    Impacted products
    Vendor Product Version
    SICK AG LMS5xx Affected: 0 , < V2.21 (*)
    Create a notification for this product.
    sick lms5xx Affected: 0 , < 2.21 (custom)
        cpe:2.3:h:sick:lms5xx:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T07:24:04.655Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "issue-tracking",
                  "x_transferred"
                ],
                "url": "https://sick.com/psirt"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0007.pdf"
              },
              {
                "tags": [
                  "x_csaf",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0007.json"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:sick:lms5xx:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "lms5xx",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThan": "2.21",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-4419",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-02T19:46:33.605067Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-09T14:12:11.224Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "LMS5xx",
              "vendor": "SICK AG",
              "versions": [
                {
                  "lessThan": "V2.21",
                  "status": "affected",
                  "version": "0",
                  "versionType": "*"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "The LMS5xx uses hard-coded credentials, which potentially allow low-skilled\nunauthorized remote attackers to reconfigure settings and /or disrupt the functionality of the device."
                }
              ],
              "value": "The LMS5xx uses hard-coded credentials, which potentially allow low-skilled\nunauthorized remote attackers to reconfigure settings and /or disrupt the functionality of the device."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Use of Hard-coded Credentials",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-01T12:14:33.487Z",
            "orgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
            "shortName": "SICK AG"
          },
          "references": [
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://sick.com/psirt"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0007.pdf"
            },
            {
              "tags": [
                "x_csaf"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0007.json"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "SICK has released a new version V2.21 of the SICK LMS5xx firmware and recommends updating to the newest version."
                }
              ],
              "value": "SICK has released a new version V2.21 of the SICK LMS5xx firmware and recommends updating to the newest version."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
        "assignerShortName": "SICK AG",
        "cveId": "CVE-2023-4419",
        "datePublished": "2023-08-24T18:08:19.977Z",
        "dateReserved": "2023-08-18T13:09:27.459Z",
        "dateUpdated": "2026-06-01T12:14:33.487Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2023-4418 (GCVE-0-2023-4418)

    Vulnerability from cvelistv5 – Published: 2023-08-24 18:05 – Updated: 2026-06-01 12:13
    VLAI
    Summary
    A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack. By exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests, overwhelming its resources and causing it to become unresponsive or unavailable for legitimate users.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-02 19:55 UTC
    CWE
    • Uncontrolled Resource Consumption
    Assigner
    Impacted products
    Vendor Product Version
    SICK AG LMS5xx Affected: all firmware versions
    Create a notification for this product.
    sick lms5xx Affected: 0 , < * (custom)
        cpe:2.3:h:sick:lms5xx:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T07:24:04.985Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "issue-tracking",
                  "x_transferred"
                ],
                "url": "https://sick.com/psirt"
              },
              {
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0007.pdf"
              },
              {
                "tags": [
                  "x_csaf",
                  "x_transferred"
                ],
                "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0007.json"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:sick:lms5xx:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "lms5xx",
                "vendor": "sick",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-4418",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-02T19:55:17.446547Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-09T14:12:17.603Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "product": "LMS5xx",
              "vendor": "SICK AG",
              "versions": [
                {
                  "status": "affected",
                  "version": "all firmware versions"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack. \nBy exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests, overwhelming its resources and causing it to become unresponsive or unavailable for legitimate users."
                }
              ],
              "value": "A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack. \nBy exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests, overwhelming its resources and causing it to become unresponsive or unavailable for legitimate users."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Uncontrolled Resource Consumption",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-01T12:13:15.780Z",
            "orgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
            "shortName": "SICK AG"
          },
          "references": [
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://sick.com/psirt"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0007.pdf"
            },
            {
              "tags": [
                "x_csaf"
              ],
              "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0007.json"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Please make sure that you apply general security practices when operating the LMS5xx. The following General Security Practices and Operating Guidelines could mitigate the associated security risk. It is also recommended to apply the security practices listed in the LMS5xx hardening guide."
                }
              ],
              "value": "Please make sure that you apply general security practices when operating the LMS5xx. The following General Security Practices and Operating Guidelines could mitigate the associated security risk. It is also recommended to apply the security practices listed in the LMS5xx hardening guide."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
        "assignerShortName": "SICK AG",
        "cveId": "CVE-2023-4418",
        "datePublished": "2023-08-24T18:05:15.123Z",
        "dateReserved": "2023-08-18T13:09:11.346Z",
        "dateUpdated": "2026-06-01T12:13:15.780Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2019-10979 (GCVE-0-2019-10979)

    Vulnerability from cvelistv5 – Published: 2019-07-01 20:05 – Updated: 2024-08-04 22:40
    VLAI
    Summary
    SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password.
    Severity
    No CVSS data available.
    CWE
    • CWE-798 - USE OF HARD-CODED CREDENTIALS CWE-798
    References
    Impacted products
    Vendor Product Version
    SICK MSC800 Affected: all versions prior to Version 4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T22:40:15.569Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "108924",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/108924"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.us-cert.gov/ics/advisories/icsa-19-178-04"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://www.sick.com/de/en/service-and-support/the-sick-product-security-incident-response-team-sick-psirt/w/psirt/#advisories"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "MSC800",
              "vendor": "SICK",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions prior to Version 4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-798",
                  "description": "USE OF HARD-CODED CREDENTIALS CWE-798",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-08-01T12:53:22.000Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "name": "108924",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/108924"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.us-cert.gov/ics/advisories/icsa-19-178-04"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://www.sick.com/de/en/service-and-support/the-sick-product-security-incident-response-team-sick-psirt/w/psirt/#advisories"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "ics-cert@hq.dhs.gov",
              "ID": "CVE-2019-10979",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "MSC800",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "all versions prior to Version 4.0"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "SICK"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "USE OF HARD-CODED CREDENTIALS CWE-798"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "108924",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/108924"
                },
                {
                  "name": "https://www.us-cert.gov/ics/advisories/icsa-19-178-04",
                  "refsource": "MISC",
                  "url": "https://www.us-cert.gov/ics/advisories/icsa-19-178-04"
                },
                {
                  "name": "https://www.sick.com/de/en/service-and-support/the-sick-product-security-incident-response-team-sick-psirt/w/psirt/#advisories",
                  "refsource": "CONFIRM",
                  "url": "https://www.sick.com/de/en/service-and-support/the-sick-product-security-incident-response-team-sick-psirt/w/psirt/#advisories"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2019-10979",
        "datePublished": "2019-07-01T20:05:10.000Z",
        "dateReserved": "2019-04-08T00:00:00.000Z",
        "dateUpdated": "2024-08-04T22:40:15.569Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }