« Volver al listado

CVE-2023-23445

Estado: ModificadaAlta (7.5)—

Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to gain unauthorized access to data fields by using a therefore unpriviledged account via the REST interface.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (7)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-23445",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-23445",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-01-23T19:17:53.365000Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@sick.de",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@sick.de",
      "affectedData": [
        {
          "vendor": "SICK AG",
          "product": "SICK FTMG-ESD15AXX AIR FLOW SENSOR",
          "versions": [
            {
              "status": "affected",
              "version": "all firmware versions"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "SICK AG",
          "product": "SICK FTMG-ESD20AXX AIR FLOW SENSOR",
          "versions": [
            {
              "status": "affected",
              "version": "all firmware versions"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "SICK AG",
          "product": "SICK FTMG-ESD25AXX AIR FLOW SENSOR",
          "versions": [
            {
              "status": "affected",
              "version": "all firmware versions"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "SICK AG",
          "product": "SICK FTMG-ESN40SXX AIR FLOW SENSOR",
          "versions": [
            {
              "status": "affected",
              "version": "all firmware versions"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "SICK AG",
          "product": "SICK FTMG-ESN50SXX AIR FLOW SENSOR",
          "versions": [
            {
              "status": "affected",
              "version": "all firmware versions"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "SICK AG",
          "product": "SICK FTMG-ESR40SXX AIR FLOW SENSOR",
          "versions": [
            {
              "status": "affected",
              "version": "all firmware versions"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "SICK AG",
          "product": "SICK FTMG-ESR50SXX AIR FLOW SENSOR",
          "versions": [
            {
              "status": "affected",
              "version": "all firmware versions"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2023-05-15T11:15:09.087",
  "references": [
    {
      "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.json",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@sick.de"
    },
    {
      "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@sick.de"
    },
    {
      "url": "https://sick.com/psirt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@sick.de"
    },
    {
      "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.json",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://sick.com/psirt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@sick.de",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers\n1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote\nattacker to gain unauthorized access to data fields by using a therefore unpriviledged account via the\nREST interface."
    }
  ],
  "lastModified": "2026-06-17T05:37:09.097",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sick:ftmg-esd20axx_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E3882685-8678-47E4-995C-C3F6D9AD5668",
              "versionEndExcluding": "2.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sick:ftmg-esd20axx:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "16AD808F-900B-41EE-B90A-F9D67AAAD6BE"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sick:ftmg-esd25axx_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "49D930E8-415C-4183-87A1-8D7F44247B67",
              "versionEndExcluding": "2.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sick:ftmg-esd25axx:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "24618A95-328C-47C9-B8EF-B4DF6E65D68E"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sick:ftmg-esn40sxx_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1DCC9C0B-7CCE-44E5-B25D-67BF971B4541",
              "versionEndExcluding": "2.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sick:ftmg-esn40sxx:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "290B016B-20B7-40C1-B825-6ED4774C4861"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sick:ftmg-esn50sxx_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E23D6018-1DFB-4516-82C9-3A3B09C2CBF9",
              "versionEndExcluding": "2.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sick:ftmg-esn50sxx:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1B113D9E-8E61-4F9C-9E5B-2030EEFB133B"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sick:ftmg-esr50sxx_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "77F2683F-B1B5-4033-97D4-ADF77B6B50E8",
              "versionEndExcluding": "2.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sick:ftmg-esr50sxx:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A02547D3-5E40-41B3-A7B4-D63F60A5F80B"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sick:ftmg-esr40sxx_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9075A02A-C627-43DA-ACF7-776197B518C5",
              "versionEndExcluding": "2.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sick:ftmg-esr40sxx:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "7B887993-18A8-493F-97A1-A788FBD5A5B9"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sick:ftmg-esd15axx_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9219CD8-34CE-45A2-904A-E7B1740706C2",
              "versionEndExcluding": "2.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sick:ftmg-esd15axx:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FF162AA9-6645-4032-8D29-BAE2D60FBD9B"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@sick.de"
}