A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By exploiting these plaintext credentials, an attacker can log into affected SICK products as an “Authorized Client” if the customer has not changed the default password.
History

Thu, 17 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Sick
Sick clv620 Firmware
Sick clv621 Firmware
Sick clv622 Firmware
Sick clv630 Firmware
Sick clv631 Firmware
Sick clv632 Firmware
Sick clv640 Firmware
Sick clv642 Firmware
Sick clv650 Firmware
Sick clv651 Firmware
Sick lector610 Firmware
Sick lector611 Firmware
Sick lector620 Firmware
Sick lector621 Firmware
Sick lector622 Firmware
Sick lector630 Firmware
Sick lector632 Firmware
Sick lector640 Firmware
Sick lector642 Firmware
Sick lector650 Firmware
Sick lector651 Firmware
Sick lector654 Firmware
Sick rfu610-10600 Firmware
Sick rfu610-10601 Firmware
Sick rfu610-10603 Firmware
Sick rfu610-10604 Firmware
Sick rfu610-10605 Firmware
Sick rfu610-10607 Firmware
Sick rfu610-10609 Firmware
Sick rfu610-10610 Firmware
Sick rfu610-10613 Firmware
Sick rfu610-10614 Firmware
Sick rfu610-10618 Firmware
Sick rfu610-10700 Firmware
Sick rfu620-10100 Firmware
Sick rfu620-10101 Firmware
Sick rfu620-10102 Firmware
Sick rfu620-10103 Firmware
Sick rfu620-10104 Firmware
Sick rfu620-10105 Firmware
Sick rfu620-10107 Firmware
Sick rfu620-10108 Firmware
Sick rfu620-10111 Firmware
Sick rfu620-10114 Firmware
Sick rfu620-10118 Firmware
Sick rfu620-10400 Firmware
Sick rfu620-10401 Firmware
Sick rfu620-10500 Firmware
Sick rfu620-10501 Firmware
Sick rfu620-10503 Firmware
Sick rfu620-10504 Firmware
Sick rfu620-10507 Firmware
CPEs cpe:2.3:o:sick:clv620_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:clv621_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:clv622_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:clv630_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:clv631_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:clv632_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:clv640_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:clv642_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:clv650_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:clv651_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:lector610_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sick:lector611_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sick:lector620_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:lector621_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:lector622_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:lector630_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:lector632_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:lector640_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:lector642_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:lector650_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:lector651_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:lector654_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu610-10600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu610-10601_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu610-10603_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu610-10604_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu610-10605_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu610-10607_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu610-10609_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu610-10610_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu610-10613_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu610-10614_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu610-10618_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu610-10700_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu620-10100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu620-10101_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu620-10102_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu620-10103_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu620-10104_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu620-10105_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu620-10107_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu620-10108_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu620-10111_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu620-10114_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu620-10118_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu620-10400_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu620-10401_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu620-10500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu620-10501_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu620-10503_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu620-10504_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:rfu620-10507_firmware:-:*:*:*:*:*:*:*
Vendors & Products Sick
Sick clv620 Firmware
Sick clv621 Firmware
Sick clv622 Firmware
Sick clv630 Firmware
Sick clv631 Firmware
Sick clv632 Firmware
Sick clv640 Firmware
Sick clv642 Firmware
Sick clv650 Firmware
Sick clv651 Firmware
Sick lector610 Firmware
Sick lector611 Firmware
Sick lector620 Firmware
Sick lector621 Firmware
Sick lector622 Firmware
Sick lector630 Firmware
Sick lector632 Firmware
Sick lector640 Firmware
Sick lector642 Firmware
Sick lector650 Firmware
Sick lector651 Firmware
Sick lector654 Firmware
Sick rfu610-10600 Firmware
Sick rfu610-10601 Firmware
Sick rfu610-10603 Firmware
Sick rfu610-10604 Firmware
Sick rfu610-10605 Firmware
Sick rfu610-10607 Firmware
Sick rfu610-10609 Firmware
Sick rfu610-10610 Firmware
Sick rfu610-10613 Firmware
Sick rfu610-10614 Firmware
Sick rfu610-10618 Firmware
Sick rfu610-10700 Firmware
Sick rfu620-10100 Firmware
Sick rfu620-10101 Firmware
Sick rfu620-10102 Firmware
Sick rfu620-10103 Firmware
Sick rfu620-10104 Firmware
Sick rfu620-10105 Firmware
Sick rfu620-10107 Firmware
Sick rfu620-10108 Firmware
Sick rfu620-10111 Firmware
Sick rfu620-10114 Firmware
Sick rfu620-10118 Firmware
Sick rfu620-10400 Firmware
Sick rfu620-10401 Firmware
Sick rfu620-10500 Firmware
Sick rfu620-10501 Firmware
Sick rfu620-10503 Firmware
Sick rfu620-10504 Firmware
Sick rfu620-10507 Firmware
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Oct 2024 10:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By exploiting these plaintext credentials, an attacker can log into affected SICK products as an “Authorized Client” if the customer has not changed the default password.
Title Vulnerability in SICK CLV6xx, SICK Lector6xx and SICK RFx6xx
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SICK AG

Published: 2024-10-17T09:58:03.111Z

Updated: 2024-10-17T16:33:53.645Z

Reserved: 2024-10-16T07:45:23.632Z

Link: CVE-2024-10025

cve-icon Vulnrichment

Updated: 2024-10-17T13:46:41.657Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-17T10:15:03.127

Modified: 2024-10-18T12:52:33.507

Link: CVE-2024-10025

cve-icon Redhat

No data.