Improper Access Control in SICK FTMg AIR FLOW SENSOR by SICK
CVE-2023-23445
7.5HIGH
Key Information:
- Vendor
- Sick Ag
- Status
- Vendor
- CVE Published:
- 15 May 2023
Summary
The SICK FTMg AIR FLOW SENSOR is affected by a vulnerability that allows a remote attacker using an unprivileged account to gain unauthorized access to critical data fields through the REST interface. This improper access control may lead to significant information exposure, putting sensitive operations at risk. Users of affected models should review their security posture and apply necessary mitigations.
Affected Version(s)
SICK FTMG-ESD15AXX AIR FLOW SENSOR all firmware versions
SICK FTMG-ESD20AXX AIR FLOW SENSOR all firmware versions
SICK FTMG-ESD25AXX AIR FLOW SENSOR all firmware versions
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved