Description
Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing
unauthenticated endpoints.
unauthenticated endpoints.
No analysis available yet.
Remediation
Vendor Solution
The recommended solution is to update the firmware to a version >= V2.5.0 as soon as possible.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-43947 | Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endpoints. |
References
History
Mon, 01 Jun 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endpoints. | Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endpoints. |
Tue, 12 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sick Ag
Sick Ag icr890-4 |
|
| CPEs | cpe:2.3:a:sick_ag:icr890-4:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sick Ag
Sick Ag icr890-4 |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: SICK AG
Published:
Updated: 2026-06-01T12:20:55.083Z
Reserved: 2023-06-15T11:32:31.460Z
Link: CVE-2023-3271
Updated: 2024-08-02T06:48:08.371Z
Status : Modified
Published: 2023-07-10T16:15:55.443
Modified: 2026-06-01T13:16:24.463
Link: CVE-2023-3271
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD