Improper Access Control Vulnerability in SICK APU FTP Server
CVE-2023-43696

8.2HIGH

Key Information:

Vendor
Sick Ag
Status
Vendor
CVE Published:
9 October 2023

Summary

The SICK APU FTP server has a vulnerability that enables unprivileged remote attackers to gain unauthorized access, allowing them to upload and download arbitrary files without authentication. This weakness can lead to significant security risks, as sensitive information may be exposed or compromised through anonymous access.

Affected Version(s)

APU0200 all versions

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.