Impact
An attacker can read and write critical files on the device’s filesystem via the AppEngine Fileaccess over HTTP endpoint that lacks proper authentication. The exposed directory includes device parameter files, such as customer‑defined passwords, and a custom application directory that can execute arbitrary Lua code within the sandboxed AppEngine environment. This combination of file system compromise and code execution could lead to total loss of configuration integrity and allow the attacker to persist or move laterally within the industrial network.
Affected Systems
SICK AG InspectorP61x, InspectorP62x, InspectorP63x, InspectorP64x, and InspectorP65x are affected. The advisory specifically recommends that users of InspectorP61x and InspectorP62x upgrade to version 5.4.0; the status for InspectorP63x–P65x versions is not explicitly defined, so administrators should verify the firmware version and consult SICK’s guidance.
Risk and Exploitability
The vulnerability has a CVSS score of 9.4 and an EPSS of less than 1 %, indicating a highly severe but currently low probability of exploitation. It is not listed in CISA KEV. Because the vulnerable endpoint is reachable without authentication, an attacker who can access the HTTP interface—typically an actor inside the industrial network or one with proxy access externally—can exploit the flaw. By reading sensitive files, altering configuration, and executing arbitrary Lua code, the attacker could fully compromise device integrity and potentially the broader control network.
OpenCVE Enrichment