Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers
1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to download files by using a therefore unpriviledged account via the REST interface.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-27546 | Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to download files by using a therefore unpriviledged account via the REST interface. |
Fixes
Solution
SICK has released a new major version v3.0.0.131.Release of the SICK FTMg firmware and recommends updating to the newest version.
Workaround
No workaround given by the vendor.
References
History
Thu, 23 Jan 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: SICK AG
Published:
Updated: 2025-01-23T19:16:29.331Z
Reserved: 2023-01-12T04:07:53.938Z
Link: CVE-2023-23446
Updated: 2024-08-02T10:28:41.041Z
Status : Modified
Published: 2023-05-15T11:15:09.160
Modified: 2024-11-21T07:46:12.857
Link: CVE-2023-23446
No data.
OpenCVE Enrichment
No data.
EUVD