Vulnerability index

Browse CVEs

116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Apu0200 Firmware CRITICAL 9.8
CVE-2023-43696

Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous access to the …

Fix: 4.0.0.6+
Fix from $2,300 2023-10-09
Apu0200 Firmware HIGH 7.5
CVE-2023-43699

Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU allows an unprivileged remote attacker to guess the password via tria…

Fix: 4.0.0.6+
Fix from $1,950 2023-10-09
Apu0200 Firmware HIGH 7.5
CVE-2023-43700

Missing Authorization in RDT400 in SICK APU allows an unprivileged remote attacker to modify data via HTTP requests that no not require authenticatio…

Fix: 4.0.0.6+
Fix from $1,950 2023-10-09
Sim1012 0p0g200 Firmware CRITICAL 9.8
CVE-2023-5288

A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings. The adversary may also reset t…

Mitigation only
Fix from $2,300 2023-09-29
Lms531 Firmware HIGH 8.8
CVE-2023-4419

The LMS5xx uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure settings and /or disrupt the…

Mitigation only
Fix from $1,950 2023-08-24
Lms531 Firmware HIGH 7.4
CVE-2023-4420

A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in th…

Mitigation only
Fix from $1,950 2023-08-24
Lms531 Firmware HIGH 7.5
CVE-2023-4418

A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) …

Mitigation only
Fix from $1,950 2023-08-24
Lms531 Firmware HIGH 7.5
CVE-2023-31412

The LMS5xx uses weak hash generation methods, resulting in the creation of insecure hashs. If an attacker manages to retrieve the hash, it could lead…

Mitigation only
Fix from $1,950 2023-08-24
Icr890 4 Firmware HIGH 7.5
CVE-2023-3270

Exposure of Sensitive Information to an Unauthorized Actor in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive …

Fix: 2.5.0+
Fix from $1,950 2023-07-10
Icr890 4 Firmware HIGH 7.5
CVE-2023-3271

Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data …

Fix: 2.5.0+
Fix from $1,950 2023-07-10
Icr890 4 Firmware HIGH 7.5
CVE-2023-3272

Cleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a remote attacker to gather sensitive information by intercepting ne…

Fix: 2.5.0+
Fix from $1,950 2023-07-10
Icr890 4 Firmware HIGH 7.5
CVE-2023-3273

Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by changing sett…

Fix: 2.5.0+
Fix from $1,950 2023-07-10
Icr890 4 Firmware HIGH 7.5
CVE-2023-35696

Unauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the device via …

Fix: 2.5.0+
Fix from $1,950 2023-07-10
Icr890 4 Firmware HIGH 7.5
CVE-2023-35697

Improper Restriction of Excessive Authentication Attempts in the SICK ICR890-4 could allow a remote attacker to brute-force user credentials.

Fix: 2.5.0+
Fix from $1,950 2023-07-10
Icr890 4 Firmware MEDIUM 5.3
CVE-2023-35698

Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the FTP server from the response g…

Fix: 2.5.0+
Fix from $1,600 2023-07-10
Sick Eventcam App CRITICAL 9.8
CVE-2023-31411

A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication. The lack of…

Mitigation only
Fix from $2,300 2023-06-19
Sick Eventcam App HIGH 7.4
CVE-2023-31410

A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in th…

Mitigation only
Fix from $1,950 2023-06-19
Ftmg Esd20axx Firmware CRITICAL 9.8
CVE-2023-23450

Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116…

Fix: 2.0+
Fix from $2,300 2023-05-15
Ftmg Esd20axx Firmware HIGH 7.5
CVE-2023-23445

Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivi…

Fix: 2.0+
Fix from $1,950 2023-05-15
Ftmg Esd20axx Firmware HIGH 7.5
CVE-2023-23446

Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivi…

Fix: 2.0+
Fix from $1,950 2023-05-15
Ftmg Esd20axx Firmware HIGH 7.5
CVE-2023-23447

Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows …

Fix: 2.0+
Fix from $1,950 2023-05-15
Ftmg Esd20axx Firmware HIGH 7.5
CVE-2023-31408

Cleartext Storage of Sensitive Information in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 112252…

Fix: 2.0+
Fix from $1,950 2023-05-15
Ftmg Esd20axx Firmware HIGH 7.5
CVE-2023-31409

Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows …

Fix: 2.0+
Fix from $1,950 2023-05-15
Ftmg Esd20axx Firmware MEDIUM 5.3
CVE-2023-23448

Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524,…

Fix: 2.0+
Fix from $1,600 2023-05-15
Ftmg Esd20axx Firmware MEDIUM 5.3
CVE-2023-23449

Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a …

Fix: 2.0+
Fix from $1,600 2023-05-15
Ue410 En4 Firmware HIGH 8.2
CVE-2023-23444

Missing Authentication for Critical Function in SICK Flexi Classic and Flexi Soft Gateways with Partnumbers 1042193, 1042964, 1044078, 1044072, 10440…

Mitigation only
Fix from $1,950 2023-05-12
Ue410 En3 Firmware CRITICAL 9.8
CVE-2023-23451

The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN1 FL…

Fix: after 2.12.0
Fix from $2,300 2023-04-19
Fx0 Gpnt00000 Firmware CRITICAL 9.8
CVE-2023-23452

Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve a…

Mitigation only
Fix from $2,300 2023-02-20
Fx0 Gent00010 Firmware CRITICAL 9.8
CVE-2023-23453

Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve a…

Mitigation only
Fix from $2,300 2023-02-20
Sim2000 Firmware CRITICAL 9.8
CVE-2022-47377

Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker to gain acc…

Fix: 1.13.4+
Fix from $2,300 2022-12-16