« Volver al listado

CVE-2023-23448

Estado: ModificadaMedia (5.3)—

Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis of source code.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (7)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-23448",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-23448",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-01-23T19:14:42.455933Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@sick.de",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@sick.de",
      "affectedData": [
        {
          "vendor": "SICK AG",
          "product": "SICK FTMG-ESD15AXX AIR FLOW SENSOR",
          "versions": [
            {
              "status": "affected",
              "version": "all firmware versions"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "SICK AG",
          "product": "SICK FTMG-ESD20AXX AIR FLOW SENSOR",
          "versions": [
            {
              "status": "affected",
              "version": "all firmware versions"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "SICK AG",
          "product": "SICK FTMG-ESD25AXX AIR FLOW SENSOR",
          "versions": [
            {
              "status": "affected",
              "version": "all firmware versions"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "SICK AG",
          "product": "SICK FTMG-ESN40SXX AIR FLOW SENSOR",
          "versions": [
            {
              "status": "affected",
              "version": "all firmware versions"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "SICK AG",
          "product": "SICK FTMG-ESN50SXX AIR FLOW SENSOR",
          "versions": [
            {
              "status": "affected",
              "version": "all firmware versions"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "SICK AG",
          "product": "SICK FTMG-ESR40SXX AIR FLOW SENSOR",
          "versions": [
            {
              "status": "affected",
              "version": "all firmware versions"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "SICK AG",
          "product": "SICK FTMG-ESR50SXX AIR FLOW SENSOR",
          "versions": [
            {
              "status": "affected",
              "version": "all firmware versions"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2023-05-15T11:15:09.280",
  "references": [
    {
      "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.json",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@sick.de"
    },
    {
      "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@sick.de"
    },
    {
      "url": "https://sick.com/psirt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@sick.de"
    },
    {
      "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.json",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://sick.com/psirt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@sick.de",
      "description": [
        {
          "lang": "en",
          "value": "CWE-540"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-668"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a\nremote attacker to gain information about valid usernames via analysis of source code."
    }
  ],
  "lastModified": "2026-06-17T05:37:09.563",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sick:ftmg-esd20axx_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E3882685-8678-47E4-995C-C3F6D9AD5668",
              "versionEndExcluding": "2.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sick:ftmg-esd20axx:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "16AD808F-900B-41EE-B90A-F9D67AAAD6BE"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sick:ftmg-esd25axx_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "49D930E8-415C-4183-87A1-8D7F44247B67",
              "versionEndExcluding": "2.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sick:ftmg-esd25axx:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "24618A95-328C-47C9-B8EF-B4DF6E65D68E"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sick:ftmg-esn40sxx_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1DCC9C0B-7CCE-44E5-B25D-67BF971B4541",
              "versionEndExcluding": "2.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sick:ftmg-esn40sxx:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "290B016B-20B7-40C1-B825-6ED4774C4861"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sick:ftmg-esn50sxx_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E23D6018-1DFB-4516-82C9-3A3B09C2CBF9",
              "versionEndExcluding": "2.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sick:ftmg-esn50sxx:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1B113D9E-8E61-4F9C-9E5B-2030EEFB133B"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sick:ftmg-esr50sxx_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "77F2683F-B1B5-4033-97D4-ADF77B6B50E8",
              "versionEndExcluding": "2.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sick:ftmg-esr50sxx:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A02547D3-5E40-41B3-A7B4-D63F60A5F80B"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sick:ftmg-esr40sxx_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9075A02A-C627-43DA-ACF7-776197B518C5",
              "versionEndExcluding": "2.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sick:ftmg-esr40sxx:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "7B887993-18A8-493F-97A1-A788FBD5A5B9"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sick:ftmg-esd15axx_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9219CD8-34CE-45A2-904A-E7B1740706C2",
              "versionEndExcluding": "2.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sick:ftmg-esd15axx:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FF162AA9-6645-4032-8D29-BAE2D60FBD9B"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@sick.de"
}