Vulnerabilities > Sick > Msc800 Firmware

DATE CVE VULNERABILITY TITLE RISK
2022-04-11 CVE-2022-27577 Use of Insufficiently Random Values vulnerability in Sick Msc800 Firmware 4.0/4.10
The vulnerability in the MSC800 in all versions before 4.15 allows for an attacker to predict the TCP initial sequence number.
network
low complexity
sick CWE-330
critical
9.1
2020-08-31 CVE-2020-2075 Improper Handling of Exceptional Conditions vulnerability in Sick products
Platform mechanism AutoIP allows remote attackers to reboot the device via a crafted packet in SICK AG solutions Bulkscan LMS111, Bulkscan LMS511, CLV62x – CLV65x, ICR890-3, LMS10x, LMS11x, LMS15x, LMS12x, LMS13x, LMS14x, LMS5xx, LMS53x, MSC800, RFH.
network
low complexity
sick CWE-755
7.5
2019-07-01 CVE-2019-10979 Use of Hard-coded Credentials vulnerability in Sick Msc800 Firmware
SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password.
network
low complexity
sick CWE-798
critical
9.8