Weak Hash Generation in LMS5xx by Sick AG
CVE-2023-31412
7.5HIGH
Summary
The LMS5xx series from Sick AG utilizes weak hash generation methods that create insecure hashes. This vulnerability poses a risk as an attacker could exploit these insecure hashes to conduct collision attacks. If successful, this may allow them to retrieve sensitive user passwords, undermining the integrity of the system's security. Organizations using the LMS5xx should evaluate their security posture and consider implementing mitigation strategies promptly.
Affected Version(s)
LMS5xx all firmware versions
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved