Remote Information Disclosure in SICK ICR890-4
CVE-2023-35696

7.5HIGH

Key Information:

Vendor
Sick Ag
Status
Vendor
CVE Published:
10 July 2023

Summary

The SICK ICR890-4 device contains unauthenticated endpoints that can be exploited by remote attackers to access sensitive device information via HTTP requests. This vulnerability poses a risk as it can potentially expose critical device details without requiring authentication, increasing the likelihood of exploitation.

Affected Version(s)

ICR890-4 0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.