Vulnerabilities > CVE-2023-35698 - Information Exposure Through Discrepancy vulnerability in Sick Icr890-4 Firmware

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
sick
CWE-203

Summary

Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the FTP server from the response given during a failed login attempt.

Vulnerable Configurations

Part Description Count
OS
Sick
1
Hardware
Sick
1

Common Weakness Enumeration (CWE)