Sick
Sick Icr890-4 Firmware: vulnerabilidades y CVE
Sick Icr890-4 Firmware tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-3273 | Alta (7.5) | 1.1% | — | 10 jul 2023 | Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by changing settings of the device such as the IP address based on missing access… |
| CVE-2023-3272 | Alta (7.5) | 0.61% | — | 10 jul 2023 | Cleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a remote attacker to gather sensitive information by intercepting network traffic that is not encrypted. |
| CVE-2023-3271 | Alta (7.5) | 0.92% | — | 10 jul 2023 | Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endpoints. |
| CVE-2023-3270 | Alta (7.5) | 0.98% | — | 10 jul 2023 | Exposure of Sensitive Information to an Unauthorized Actor in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the system. |
| CVE-2023-35699 | Media (4.6) | 0.20% | — | 10 jul 2023 | Cleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device to disclose sensitive information by accessing a SD card. |
| CVE-2023-35698 | Media (5.3) | 0.78% | — | 10 jul 2023 | Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the FTP server from the response given during a failed login attempt. |
| CVE-2023-35697 | Alta (7.5) | 0.90% | — | 10 jul 2023 | Improper Restriction of Excessive Authentication Attempts in the SICK ICR890-4 could allow a remote attacker to brute-force user credentials. |
| CVE-2023-35696 | Alta (7.5) | 0.94% | — | 10 jul 2023 | Unauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the device via HTTP requests. |