Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by changing settings of the device such as the IP
address based on missing access control.


Advisories
Source ID Title
EUVD EUVD EUVD-2023-43949 Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by changing settings of the device such as the IP address based on missing access control.
Fixes

Solution

No solution given by the vendor.


Workaround

SICK recommends to disable port 2111 & 2122 once the SICK ICR890-4 is put into operation.

History

Tue, 12 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Sick Ag
Sick Ag icr890-4
CPEs cpe:2.3:a:sick_ag:icr890-4:*:*:*:*:*:*:*:*
Vendors & Products Sick Ag
Sick Ag icr890-4
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SICK AG

Published:

Updated: 2024-11-12T14:17:56.263Z

Reserved: 2023-06-15T11:32:34.499Z

Link: CVE-2023-3273

cve-icon Vulnrichment

Updated: 2024-08-02T06:48:08.408Z

cve-icon NVD

Status : Modified

Published: 2023-07-10T16:15:55.560

Modified: 2024-11-21T08:16:52.610

Link: CVE-2023-3273

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.