Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing
unauthenticated endpoints.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-43947 Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endpoints.
Fixes

Solution

The recommended solution is to update the firmware to a version >= V2.5.0 as soon as possible.


Workaround

No workaround given by the vendor.

History

Tue, 12 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Sick Ag
Sick Ag icr890-4
CPEs cpe:2.3:a:sick_ag:icr890-4:*:*:*:*:*:*:*:*
Vendors & Products Sick Ag
Sick Ag icr890-4
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SICK AG

Published:

Updated: 2024-11-12T14:19:30.590Z

Reserved: 2023-06-15T11:32:31.460Z

Link: CVE-2023-3271

cve-icon Vulnrichment

Updated: 2024-08-02T06:48:08.371Z

cve-icon NVD

Status : Modified

Published: 2023-07-10T16:15:55.443

Modified: 2024-11-21T08:16:52.337

Link: CVE-2023-3271

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.