Improper Access Control in SICK FTMg AIR FLOW SENSOR by SICK
CVE-2023-23445

7.5HIGH

Summary

The SICK FTMg AIR FLOW SENSOR is affected by a vulnerability that allows a remote attacker using an unprivileged account to gain unauthorized access to critical data fields through the REST interface. This improper access control may lead to significant information exposure, putting sensitive operations at risk. Users of affected models should review their security posture and apply necessary mitigations.

Affected Version(s)

SICK FTMG-ESD15AXX AIR FLOW SENSOR all firmware versions

SICK FTMG-ESD20AXX AIR FLOW SENSOR all firmware versions

SICK FTMG-ESD25AXX AIR FLOW SENSOR all firmware versions

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.