Cleartext Storage Vulnerability in SICK ICR890-4
CVE-2023-35699

5.3MEDIUM

Key Information:

Vendor
Sick Ag
Status
Vendor
CVE Published:
10 July 2023

Summary

The SICK ICR890-4 device contains a vulnerability that allows an unauthenticated attacker with local access to exploit cleartext storage on the device's SD card. By accessing this storage, sensitive information may be disclosed, posing significant risks to data confidentiality and integrity. It is vital for users to understand the implications of this vulnerability and implement necessary security measures to protect their sensitive information against unauthorized access.

Affected Version(s)

ICR890-4 0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.