Vulnerabilities > Sick > High

DATE CVE VULNERABILITY TITLE RISK
2023-07-10 CVE-2023-3271 Unspecified vulnerability in Sick Icr890-4 Firmware
Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endpoints.
network
low complexity
sick
7.5
2023-07-10 CVE-2023-3272 Cleartext Transmission of Sensitive Information vulnerability in Sick Icr890-4 Firmware
Cleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a remote attacker to gather sensitive information by intercepting network traffic that is not encrypted.
network
low complexity
sick CWE-319
7.5
2023-07-10 CVE-2023-3273 Unspecified vulnerability in Sick Icr890-4 Firmware
Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by changing settings of the device such as the IP address based on missing access control.
network
low complexity
sick
7.5
2023-06-19 CVE-2023-31410 Cleartext Transmission of Sensitive Information vulnerability in Sick Eventcam APP
A remote unprivileged attacker can intercept the communication via e.g.
network
high complexity
sick CWE-319
7.4
2023-05-15 CVE-2023-23445 Incorrect Authorization vulnerability in Sick products
Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to gain unauthorized access to data fields by using a therefore unpriviledged account via the REST interface.
network
low complexity
sick CWE-863
7.5
2023-05-15 CVE-2023-23446 Incorrect Authorization vulnerability in Sick products
Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to download files by using a therefore unpriviledged account via the REST interface.
network
low complexity
sick CWE-863
7.5
2023-05-15 CVE-2023-23447 Resource Exhaustion vulnerability in Sick products
Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to influence the availability of the webserver by invocing several open file requests via the REST interface.
network
low complexity
sick CWE-400
7.5
2023-05-15 CVE-2023-31408 Cleartext Storage of Sensitive Information vulnerability in Sick products
Cleartext Storage of Sensitive Information in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to potentially steal user credentials that are stored in the user’s browsers local storage via cross-site-scripting attacks.
network
low complexity
sick CWE-312
7.5
2023-05-15 CVE-2023-31409 Resource Exhaustion vulnerability in Sick products
Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an remote attacker to influence the availability of the webserver by invocing a Slowloris style attack via HTTP requests.
network
low complexity
sick CWE-400
7.5
2023-05-12 CVE-2023-23444 Missing Authentication for Critical Function vulnerability in Sick products
Missing Authentication for Critical Function in SICK Flexi Classic and Flexi Soft Gateways with Partnumbers 1042193, 1042964, 1044078, 1044072, 1044073, 1044074, 1099830, 1099832, 1127717, 1069070, 1112296, 1051432, 1102420, 1127487, 1121596, 1121597 allows an unauthenticated remote attacker to influence the availability of the device by changing the IP settings of the device via broadcasted UDP packets.
network
low complexity
sick CWE-306
8.2