VulnerabilityModified
CVE-2023-23448
Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis of source code.
MEDIUM 5.3EPSS 0.79%
Does this matter?
Lower severity and a low EPSS score (0.79%). Track it; it rarely justifies an emergency change on its own.
Description
Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis of source code.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.79% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-540, CWE-668
- Affected
- sick/ftmg-esd20axx firmware · sick/ftmg-esd25axx firmware · sick/ftmg-esn40sxx firmware · sick/ftmg-esn50sxx firmware · sick/ftmg-esr50sxx firmware · sick/ftmg-esr40sxx firmware · sick/ftmg-esd15axx firmware
- Source
- psirt@sick.de
References
- https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.jsonVendor Advisory
- https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdfVendor Advisory
- https://sick.com/psirtVendor Advisory
- https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.jsonVendor Advisory
- https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdfVendor Advisory
- https://sick.com/psirtVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.