inludes the nonce and additional information. This challenge can be used several times for login and is
therefore vulnerable for a replay attack.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-34047 | The authentication process to the web server uses a challenge response procedure which inludes the nonce and additional information. This challenge can be used several times for login and is therefore vulnerable for a replay attack. |
Solution
No solution given by the vendor.
Workaround
As the communication is not encrypted, the device should only be used in a trusted environment.
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 06 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 06 Dec 2024 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The authentication process to the web server uses a challenge response procedure which inludes the nonce and additional information. This challenge can be used several times for login and is therefore vulnerable for a replay attack. | |
| Title | SICK InspectorP61x and SICK InspectorP62x are vulnerable for a replay attack | |
| Weaknesses | CWE-323 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: SICK AG
Published:
Updated: 2024-12-06T18:18:19.952Z
Reserved: 2024-11-08T10:39:12.918Z
Link: CVE-2024-11022
Updated: 2024-12-06T18:18:14.503Z
Status : Received
Published: 2024-12-06T13:15:06.267
Modified: 2024-12-06T13:15:06.267
Link: CVE-2024-11022
No data.
OpenCVE Enrichment
No data.
EUVD