Vulnerabilities > Sick
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-07-10 | CVE-2023-3271 | Unspecified vulnerability in Sick Icr890-4 Firmware Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endpoints. | 7.5 |
2023-07-10 | CVE-2023-3272 | Cleartext Transmission of Sensitive Information vulnerability in Sick Icr890-4 Firmware Cleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a remote attacker to gather sensitive information by intercepting network traffic that is not encrypted. | 7.5 |
2023-07-10 | CVE-2023-3273 | Unspecified vulnerability in Sick Icr890-4 Firmware Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by changing settings of the device such as the IP address based on missing access control. | 7.5 |
2023-06-19 | CVE-2023-31410 | Cleartext Transmission of Sensitive Information vulnerability in Sick Eventcam APP A remote unprivileged attacker can intercept the communication via e.g. | 7.4 |
2023-06-19 | CVE-2023-31411 | Missing Authentication for Critical Function vulnerability in Sick Eventcam APP A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication. | 9.8 |
2023-05-15 | CVE-2023-23445 | Incorrect Authorization vulnerability in Sick products Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to gain unauthorized access to data fields by using a therefore unpriviledged account via the REST interface. | 7.5 |
2023-05-15 | CVE-2023-23446 | Incorrect Authorization vulnerability in Sick products Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to download files by using a therefore unpriviledged account via the REST interface. | 7.5 |
2023-05-15 | CVE-2023-23447 | Resource Exhaustion vulnerability in Sick products Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to influence the availability of the webserver by invocing several open file requests via the REST interface. | 7.5 |
2023-05-15 | CVE-2023-23448 | Exposure of Resource to Wrong Sphere vulnerability in Sick products Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis of source code. | 5.3 |
2023-05-15 | CVE-2023-23449 | Information Exposure Through Discrepancy vulnerability in Sick products Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames by analyzing challenge responses from the server via the REST interface. | 5.3 |