Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU
allows an unprivileged remote attacker to guess the password via trial-and-error as the login attempts
are not limited.

Subscriptions

Vendors Products
Apu0200 Subscribe
Apu0200 Firmware Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-48080 Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU allows an unprivileged remote attacker to guess the password via trial-and-error as the login attempts are not limited.
Fixes

Solution

The recommended solution is to update the image to a version >= 4.0.0.6 as soon as possible.


Workaround

No workaround given by the vendor.

History

Mon, 09 Dec 2024 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:sick_ag:apu0200:*:*:*:*:*:*:*:*
Vendors & Products Sick Ag
Sick Ag apu0200

Thu, 19 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Sick Ag
Sick Ag apu0200
CPEs cpe:2.3:a:sick_ag:apu0200:*:*:*:*:*:*:*:*
Vendors & Products Sick Ag
Sick Ag apu0200
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SICK AG

Published:

Updated: 2024-12-09T13:54:43.591Z

Reserved: 2023-09-21T07:10:31.289Z

Link: CVE-2023-43699

cve-icon Vulnrichment

Updated: 2024-08-02T19:44:43.837Z

cve-icon NVD

Status : Modified

Published: 2023-10-09T12:15:10.140

Modified: 2024-11-21T08:24:35.850

Link: CVE-2023-43699

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses