SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-23446

Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to download files by using a therefore unpriviledged account via the REST interface.

HIGH 7.5EPSS 0.90%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.90%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to download files by using a therefore unpriviledged account via the REST interface.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
0.90% probability · 58th percentile
CISA KEV
Not listed
Weakness
CWE-284, CWE-863
Affected
sick/ftmg-esd20axx firmware · sick/ftmg-esd25axx firmware · sick/ftmg-esn40sxx firmware · sick/ftmg-esn50sxx firmware · sick/ftmg-esr50sxx firmware · sick/ftmg-esr40sxx firmware · sick/ftmg-esd15axx firmware
Source
psirt@sick.de

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.