Authorization Flaw in RDT400 Product by SICK
CVE-2023-43700

7.7HIGH

Key Information:

Vendor

Sick Ag

Status
Vendor
CVE Published:
9 October 2023

What is CVE-2023-43700?

The RDT400 product by SICK is susceptible to an authorization flaw that allows unauthenticated remote attackers to modify data through HTTP requests. This vulnerability undermines the integrity of the system, as it permits unauthorized changes without requiring any form of authentication, potentially leading to data loss or corruption. Users of the affected versions are advised to assess their security measures and implement necessary patches to safeguard their systems.

Affected Version(s)

APU0200 all versions

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.