Unauthorized Access to Lua Apps Through AppManager
CVE-2024-10776
8.2HIGH
Key Information:
- Vendor
- Sick Ag
- Vendor
- CVE Published:
- 6 December 2024
Summary
A vulnerability has been identified in SICK's AppManager, allowing unauthorized interactions with Lua applications. This issue permits unauthorized users to deploy, remove, start, reload, or stop applications without appropriate permissions. As a result, an attacker could potentially disrupt legitimate applications, leading to a denial of service (DoS) condition. Furthermore, this vulnerability enables the attacker to read and write files or to load malicious applications that exploit the full range of features available to legitimate users. Proper security measures must be taken to mitigate this risk.
Affected Version(s)
SICK InspectorP61x 0
SICK InspectorP62x 0
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Manuel Stotz
Tobias Jaeger