The product is vulnerable to pass-the-hash attacks in combination with hardcoded credentials of hidden user levels. This means that an attacker can log in with the hidden user levels and gain full access to the device.
History

Mon, 09 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Sick
Sick inspector61x Firmware
Sick inspector62x Firmware
Sick tim3xx
CPEs cpe:2.3:a:sick:tim3xx:*:*:*:*:*:*:*:*
cpe:2.3:o:sick:inspector61x_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:inspector62x_firmware:-:*:*:*:*:*:*:*
Vendors & Products Sick
Sick inspector61x Firmware
Sick inspector62x Firmware
Sick tim3xx
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 06 Dec 2024 13:00:00 +0000

Type Values Removed Values Added
Description The product is vulnerable to pass-the-hash attacks in combination with hardcoded credentials of hidden user levels. This means that an attacker can log in with the hidden user levels and gain full access to the device.
Title SICK InspectorP61x, SICK InspectorP62x and SICK TiM3xx are vulnerable for pass-the-hash attacks
Weaknesses CWE-912
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SICK AG

Published: 2024-12-06T12:31:10.776Z

Updated: 2024-12-09T14:44:36.597Z

Reserved: 2024-11-04T13:07:00.547Z

Link: CVE-2024-10773

cve-icon Vulnrichment

Updated: 2024-12-09T14:44:30.362Z

cve-icon NVD

Status : Received

Published: 2024-12-06T13:15:05.897

Modified: 2024-12-06T13:15:05.897

Link: CVE-2024-10773

cve-icon Redhat

No data.