Vulnerabilidades em SICK AG

113 resultados
Análise Vexday

O portfólio de vulnerabilidades da SICK AG reúne 112 CVEs catalogadas, com 14 classificadas como severidade crítica, mas nenhuma atualmente registrada no catálogo CISA KEV de exploração ativa — taxa abaixo da média geral do catálogo, o que sugere pressão ofensiva relativamente contida sobre os produtos da empresa. A ausência de PoCs públicas e de novas CVEs nos últimos 90 dias reforça um cenário de superfície de ataque estável no curto prazo. A falha mais comum é CWE-284 (controle de acesso impróprio), categoria que tende a ser crítica em ambientes de tecnologia operacional e dispositivos industriais, domínio típico da SICK AG. A CVE mais perigosa ativa, CVE-2023-23444, apresenta EPSS de 0,0117, indicando probabilidade de exploração baixa no momento, mas seu monitoramento contínuo é recomendado dado o contexto de infraestrutura industrial em que esses ativos costumam operar.

CVE-2023-23450MEDIUMUse of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114EPSS 0.7%CVE-2023-4419CRITICALThe LMS5xx uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure settings and /or diEPSS 0.7%CVE-2023-4418HIGHA remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-servicEPSS 0.7%CVE-2026-2330CRITICALCVE-2026-2330EPSS 0.7%CVE-2023-23445HIGHImproper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows aEPSS 0.7%CVE-2023-5288CRITICAL A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings. The adversary may alEPSS 0.6%CVE-2023-43697MEDIUM Modification of Assumed-Immutable Data (MAID) in RDT400 in SICK APU allows an unprivileged remote attacker to make the site unable to load EPSS 0.6%CVE-2023-43696HIGH Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous acceEPSS 0.6%CVE-2023-43700HIGHMissing Authorization in RDT400 in SICK APU allows an unprivileged remote attacker to modify data via HTTP requests that no not require authEPSS 0.6%CVE-2025-32470HIGHUnauthenticated change of IP adressEPSS 0.6%CVE-2023-3272HIGHCleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a remote attacker to gather sensitive information by intercEPSS 0.6%CVE-2025-0867CRITICALPrivilege Escalation in MEAC300EPSS 0.6%CVE-2025-32472MEDIUMDoS attack by conducting a slowloris-type attackEPSS 0.6%CVE-2024-10773CRITICALSICK InspectorP61x, SICK InspectorP62x and SICK TiM3xx are vulnerable for pass-the-hash attacksEPSS 0.6%CVE-2023-5101MEDIUM Files or Directories Accessible to External Parties in RDT400 in SICK APU allows an unprivileged remote attacker to download various files EPSS 0.6%CVE-2023-5102MEDIUM Insufficient Control Flow Management in RDT400 in SICK APU allows an unprivileged remote attacker to potentially enable hidden functionalitEPSS 0.6%CVE-2026-22908CRITICALUploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity EPSS 0.5%CVE-2025-27595CRITICALWeak hashing alghrythmEPSS 0.5%CVE-2025-58582MEDIUMUncontrolled Resource Consumption via log fileEPSS 0.5%CVE-2026-22909HIGHCertain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, EPSS 0.5%