CVE-2023-23445
Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to gain unauthorized access to data fields by using a therefore unpriviledged…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to gain unauthorized access to data fields by using a therefore unpriviledged account via the REST interface.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.66% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284, CWE-863
- Affected
- sick/ftmg-esd20axx firmware · sick/ftmg-esd25axx firmware · sick/ftmg-esn40sxx firmware · sick/ftmg-esn50sxx firmware · sick/ftmg-esr50sxx firmware · sick/ftmg-esr40sxx firmware · sick/ftmg-esd15axx firmware
- Source
- psirt@sick.de
References
- https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.jsonVendor Advisory
- https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdfVendor Advisory
- https://sick.com/psirtVendor Advisory
- https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.jsonVendor Advisory
- https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdfVendor Advisory
- https://sick.com/psirtVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.