Sick
Sick Apu0200 Firmware: vulnerabilidades y CVE
Sick Apu0200 Firmware tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-5103 | Media (4.3) | 0.45% | — | 9 oct 2023 | Improper Restriction of Rendered UI Layers or Frames in RDT400 in SICK APU allows an unprivileged remote attacker to potentially reveal sensitive information via tricking a user into clicking on an actionable item using… |
| CVE-2023-5102 | Media (5.3) | 0.57% | — | 9 oct 2023 | Insufficient Control Flow Management in RDT400 in SICK APU allows an unprivileged remote attacker to potentially enable hidden functionality via HTTP requests. |
| CVE-2023-5101 | Media (5.3) | 0.57% | — | 9 oct 2023 | Files or Directories Accessible to External Parties in RDT400 in SICK APU allows an unprivileged remote attacker to download various files from the server via HTTP requests. |
| CVE-2023-5100 | Media (6.5) | 0.35% | — | 9 oct 2023 | Cleartext Transmission of Sensitive Information in RDT400 in SICK APU allows an unprivileged remote attacker to retrieve potentially sensitive information via intercepting network traffic that is not encrypted. |
| CVE-2023-43698 | Media (6.1) | 0.48% | — | 9 oct 2023 | Improper Neutralization of Input During Web Page Generation (’Cross-site Scripting’) in RDT400 in SICK APU allows an unprivileged remote attacker to run arbitrary code in the clients browser via injecting code into the… |
| CVE-2023-43697 | Media (6.5) | 0.65% | — | 9 oct 2023 | Modification of Assumed-Immutable Data (MAID) in RDT400 in SICK APU allows an unprivileged remote attacker to make the site unable to load necessary strings via changing file paths using HTTP requests. |
| CVE-2023-43700 | Alta (7.5) | 0.63% | — | 9 oct 2023 | Missing Authorization in RDT400 in SICK APU allows an unprivileged remote attacker to modify data via HTTP requests that no not require authentication. |
| CVE-2023-43699 | Alta (7.5) | 0.72% | — | 9 oct 2023 | Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU allows an unprivileged remote attacker to guess the password via trial-and-error as the login attempts are not limited. |
| CVE-2023-43696 | Crítica (9.8) | 0.65% | — | 9 oct 2023 | Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous access to the FTP server. |