Vulnerabilities > Sick > Ftmg Esr50Sxx Firmware

DATE CVE VULNERABILITY TITLE RISK
2023-05-15 CVE-2023-23445 Incorrect Authorization vulnerability in Sick products
Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to gain unauthorized access to data fields by using a therefore unpriviledged account via the REST interface.
network
low complexity
sick CWE-863
7.5
2023-05-15 CVE-2023-23446 Incorrect Authorization vulnerability in Sick products
Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to download files by using a therefore unpriviledged account via the REST interface.
network
low complexity
sick CWE-863
7.5
2023-05-15 CVE-2023-23447 Resource Exhaustion vulnerability in Sick products
Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to influence the availability of the webserver by invocing several open file requests via the REST interface.
network
low complexity
sick CWE-400
7.5
2023-05-15 CVE-2023-23448 Exposure of Resource to Wrong Sphere vulnerability in Sick products
Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis of source code.
network
low complexity
sick CWE-668
5.3
2023-05-15 CVE-2023-23449 Information Exposure Through Discrepancy vulnerability in Sick products
Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames by analyzing challenge responses from the server via the REST interface.
network
low complexity
sick CWE-203
5.3
2023-05-15 CVE-2023-23450 Improper Authentication vulnerability in Sick products
Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to use a password hash instead of an actual password to login to a valid user account via the REST interface.
network
low complexity
sick CWE-287
critical
9.8
2023-05-15 CVE-2023-31408 Cleartext Storage of Sensitive Information vulnerability in Sick products
Cleartext Storage of Sensitive Information in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to potentially steal user credentials that are stored in the user’s browsers local storage via cross-site-scripting attacks.
network
low complexity
sick CWE-312
7.5
2023-05-15 CVE-2023-31409 Resource Exhaustion vulnerability in Sick products
Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an remote attacker to influence the availability of the webserver by invocing a Slowloris style attack via HTTP requests.
network
low complexity
sick CWE-400
7.5