S

Sick Security Vulnerabilities (CVE)

Explore vulnerabilities and security advisories affecting Sick products.

15 known CVE vulnerabilities tracked

Critical
0
High
7
Medium
8
Low
0
None
0

Vulnerabilities By Year

Products Affected

All Sick CVEs

CVE-2023-3273
7.5 high

Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by changing settings of the device such as the IP address based on missing access control.

Icr890-4 Firmware Jul 10, 2023
CVE-2023-3272
7.5 high

Cleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a remote attacker to gather sensitive information by intercepting network traffic that is not encrypted.

Icr890-4 Firmware Jul 10, 2023
CVE-2023-3271
8.2 high

Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endpoints.

Icr890-4 Firmware Jul 10, 2023
CVE-2023-35699
5.3 medium

Cleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device to disclose sensitive information by accessing a SD card.

Icr890-4 Firmware Jul 10, 2023
CVE-2023-35698
5.3 medium

Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the FTP server from the response given during a failed login attempt.

Icr890-4 Firmware Jul 10, 2023
CVE-2023-35697
5.3 medium

Improper Restriction of Excessive Authentication Attempts in the SICK ICR890-4 could allow a remote attacker to brute-force user credentials.

Icr890-4 Firmware Jul 10, 2023
CVE-2023-35696
7.5 high

Unauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the device via HTTP requests.

Icr890-4 Firmware Jul 10, 2023
CVE-2023-31409
5.3 medium

Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an remote attacker to influence the availability of the webserver by invocing a Slowloris style attack via HTTP requests.

Ftmg-Esd20Axx Firmware May 15, 2023
CVE-2023-31408
5.3 medium

Cleartext Storage of Sensitive Information in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to potentially steal user credentials that are stored in the user’s browsers local storage via cross-site-scripting attacks.

Ftmg-Esd20Axx Firmware May 15, 2023
CVE-2023-23450
6.2 medium

Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to use a password hash instead of an actual password to login to a valid user account via the

Ftmg-Esd20Axx Firmware May 15, 2023
CVE-2023-23449
5.3 medium

Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames by analyzing challenge responses from the server via the REST interface.

Ftmg-Esd20Axx Firmware May 15, 2023
CVE-2023-23448
5.3 medium

Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis of source code.

Ftmg-Esd20Axx Firmware May 15, 2023
CVE-2023-23447
7.5 high

Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to influence the availability of the webserver by invocing several open file requests via the REST interface.

Ftmg-Esd20Axx Firmware May 15, 2023
CVE-2023-23446
7.5 high

Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to download files by using a therefore unpriviledged account via the REST interface.

Ftmg-Esd20Axx Firmware May 15, 2023
CVE-2023-23445
7.5 high

Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to gain unauthorized access to data fields by using a therefore unpriviledged account via the REST interface.

Ftmg-Esd20Axx Firmware May 15, 2023