CVE-2023-5246
Estado: ModificadaAlta (8.8)—
Authentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073, 1127717, 1130282, 1044074, 1121597, 1099832, 1051432, 1127487, 1069070, 1112296, 1044072, 1121596, 1099830 allows an unauthenticated remote attacker to potentially impact the availability, integrity and confidentiality of the gateways via an authentication bypass by capture-replay.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.78%
- Percentil entre todas las CVEs puntuadas: 54
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (13)
Sick — Fx0-gent00000 FirmwareSick — Fx0-gent00010 FirmwareSick — Fx0-gent00030 FirmwareSick — Fx0-gepr00000 FirmwareSick — Fx0-gepr00010 FirmwareSick — Fx0-get00000 FirmwareSick — Fx0-get00010 FirmwareSick — Fx0-gmod00000 FirmwareSick — Fx0-gmod00010 FirmwareSick — Fx0-gmod00030 FirmwareSick — Fx0-gpnt00000 FirmwareSick — Fx0-gpnt00010 FirmwareSick — Fx0-gpnt00030 Firmware
CWE
- CWE-287
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-5246",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-5246",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-09-11T15:28:47.832868Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@sick.de",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "psirt@sick.de",
"affectedData": [
{
"vendor": "SICK AG",
"product": "FX0-GMOD00000",
"versions": [
{
"status": "affected",
"version": "vers:all/*"
}
],
"defaultStatus": "affected"
},
{
"vendor": "SICK AG",
"product": "FX0-GMOD00010",
"versions": [
{
"status": "affected",
"version": "vers:all/*"
}
],
"defaultStatus": "affected"
},
{
"vendor": "SICK AG",
"product": "FX0-GMOD00030",
"versions": [
{
"status": "affected",
"version": "vers:all/*"
}
],
"defaultStatus": "affected"
},
{
"vendor": "SICK AG",
"product": "FX0-GPNT00000",
"versions": [
{
"status": "affected",
"version": "vers:all/*"
}
],
"defaultStatus": "affected"
},
{
"vendor": "SICK AG",
"product": "FX0-GPNT00010",
"versions": [
{
"status": "affected",
"version": "vers:all/*"
}
],
"defaultStatus": "affected"
},
{
"vendor": "SICK AG",
"product": "FX0-GPNT00030",
"versions": [
{
"status": "affected",
"version": "vers:all/*"
}
],
"defaultStatus": "affected"
},
{
"vendor": "SICK AG",
"product": "FX0-GETC00000",
"versions": [
{
"status": "affected",
"version": "vers:all/*"
}
],
"defaultStatus": "affected"
},
{
"vendor": "SICK AG",
"product": "FX0-GETC00010",
"versions": [
{
"status": "affected",
"version": "vers:all/*"
}
],
"defaultStatus": "affected"
},
{
"vendor": "SICK AG",
"product": "FX3-GEPR00000",
"versions": [
{
"status": "affected",
"version": "vers:all/*"
}
],
"defaultStatus": "affected"
},
{
"vendor": "SICK AG",
"product": "FX3-GEPR00010",
"versions": [
{
"status": "affected",
"version": "vers:all/*"
}
],
"defaultStatus": "affected"
},
{
"vendor": "SICK AG",
"product": "FX0-GENT00000",
"versions": [
{
"status": "affected",
"version": "vers:all/*"
}
],
"defaultStatus": "affected"
},
{
"vendor": "SICK AG",
"product": "FX0-GENT00010",
"versions": [
{
"status": "affected",
"version": "vers:all/*"
}
],
"defaultStatus": "affected"
},
{
"vendor": "SICK AG",
"product": "FX0-GENT00030",
"versions": [
{
"status": "affected",
"version": "vers:all/*"
}
],
"defaultStatus": "affected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:o:sick:fx0-gmod00000_firmware:-:*:*:*:*:*:*:*"
],
"vendor": "sick",
"product": "fx0-gmod00000_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "*"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:sick:fx0-gmod00010_firmware:-:*:*:*:*:*:*:*"
],
"vendor": "sick",
"product": "fx0-gmod00010_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "*"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:sick:fx0-gmod00030_firmware:-:*:*:*:*:*:*:*"
],
"vendor": "sick",
"product": "fx0-gmod00030_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "*"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:sick:fx0-gpnt00000_firmware:-:*:*:*:*:*:*:*"
],
"vendor": "sick",
"product": "fx0-gpnt00000_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "*"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:sick:fx0-gpnt00010_firmware:-:*:*:*:*:*:*:*"
],
"vendor": "sick",
"product": "fx0-gpnt00010_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "*"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:sick:fx0-gpnt00030_firmware:-:*:*:*:*:*:*:*"
],
"vendor": "sick",
"product": "fx0-gpnt00030_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "*"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:sick:fx0-getc00000:*:*:*:*:*:*:*:*"
],
"vendor": "sick",
"product": "fx0-getc00000",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "*"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:sick:fx0-getc00010:*:*:*:*:*:*:*:*"
],
"vendor": "sick",
"product": "fx0-getc00010",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "*"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:sick:fx3-gepr00000:*:*:*:*:*:*:*:*"
],
"vendor": "sick",
"product": "fx3-gepr00000",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "*"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:sick:fx3-gepr00010:*:*:*:*:*:*:*:*"
],
"vendor": "sick",
"product": "fx3-gepr00010",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "*"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:sick:fx0-gent00000_firmware:-:*:*:*:*:*:*:*"
],
"vendor": "sick",
"product": "fx0-gent00000_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "*"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:sick:fx0-gent00010_firmware:-:*:*:*:*:*:*:*"
],
"vendor": "sick",
"product": "fx0-gent00010_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "*"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:o:sick:fx0-gent00030_firmware:-:*:*:*:*:*:*:*"
],
"vendor": "sick",
"product": "fx0-gent00030_firmware",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "*"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2023-10-23T13:15:09.087",
"references": [
{
"url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0011.json",
"tags": [
"Vendor Advisory"
],
"source": "psirt@sick.de"
},
{
"url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0011.pdf",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "psirt@sick.de"
},
{
"url": "https://sick.com/psirt",
"tags": [
"Vendor Advisory"
],
"source": "psirt@sick.de"
},
{
"url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0011.json",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://sick.com/.well-known/csaf/white/2023/sca-2023-0011.pdf",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://sick.com/psirt",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Authentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073, 1127717, 1130282, 1044074, 1121597, 1099832, 1051432, 1127487, 1069070, 1112296, 1044072, 1121596, 1099830 allows an unauthenticated remote attacker to potentially impact the availability, integrity and confidentiality of the gateways via an authentication bypass by capture-replay."
},
{
"lang": "es",
"value": "Omisión de autenticación mediante Capture-replay en SICK Flexi Soft Gateways con números de pieza 1044073, 1127717, 1130282, 1044074, 1121597, 1099832, 1051432, 1127487, 1069070, 1112296, 1044072, 1121596, 1099830 permite que un atacante remoto no autenticado afecte potencialmente la disponibilidad y la integridad y confidencialidad de las puertas de enlace mediante una omisión de autenticación mediante capture-replay."
}
],
"lastModified": "2026-06-17T06:48:10.180",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sick:fx0-gent00000_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8E8B658A-49DD-4F7C-9A20-191C8F6F3D8F"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sick:fx0-gent00000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "EAB590A4-F5E4-4A17-B5A6-33A995C96BAB"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sick:fx0-gent00010_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "61689FA0-FB90-4E9F-B500-AADCF8D827BE"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sick:fx0-gent00010:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BBAC00EB-BB15-4A65-A58D-B3015F7CFF85"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sick:fx0-gent00030_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "896EDB87-DB8E-4D82-83EB-65403F23FEB7"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sick:fx0-gent00030:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1809BCF9-541E-4348-87A3-4CB37D680704"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sick:fx0-get00000_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B04537E8-8C53-4CB7-BEB8-C2CDB15FEC3D"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sick:fx0-get00000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F0A0E589-9A9F-4ABF-A1D0-53DE376D6E07"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sick:fx0-get00010_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DDBC09BA-A57C-4CAA-B6B7-6FC7922E3862"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sick:fx0-get00010:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E01C2381-4CC3-49C7-A4FE-9A37754C2AA6"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sick:fx0-gmod00000_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8E87CA0E-7749-4F1E-B30B-78183ACF3170"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sick:fx0-gmod00000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D96296E7-65D3-4C0A-8126-4AA8BEF85B39"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sick:fx0-gmod00010_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "925AD219-B3D3-42B6-99E6-E97298AE0A4C"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sick:fx0-gmod00010:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "97742720-A8E3-49FE-BE43-EFF720F3D52D"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sick:fx0-gmod00030_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "949735C8-09BE-453C-B83A-8BF80BD370B6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sick:fx0-gmod00030:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2F18250E-A899-4210-A0D3-087438EFCEA3"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sick:fx0-gpnt00000_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "30BF991A-B66F-48B3-8902-D50C3B38A30D"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sick:fx0-gpnt00000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BF3BF752-4F49-4E90-9790-1913ED64D8B3"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sick:fx0-gpnt00010_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "00770E9A-64BC-4440-A921-49ECD5C5986D"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sick:fx0-gpnt00010:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "60B6F37A-78EE-4D1F-ACAE-FDE864F847B8"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sick:fx0-gpnt00030_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9447F86A-5967-4C97-AF69-369EF2BD2052"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sick:fx0-gpnt00030:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4CABEFF4-C0A4-4054-8174-7B3762BC0C3F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sick:fx0-gepr00000_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B08EEEB3-7310-4382-9C30-B1F6CBC69582"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sick:fx0-gepr00000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "41E76E7E-9840-4E37-A554-D0DE70E178E0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sick:fx0-gepr00010_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "56AF0E16-E0E7-4B5D-ABE3-02E27B4F9AC6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sick:fx0-gepr00010:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F2D5EB09-6970-4CD7-BE09-D563E73B55F0"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@sick.de"
}