Unauthorized Access to Lua Apps Through AppManager
CVE-2024-10776

8.2HIGH

Key Information:

Vendor
Sick Ag
Vendor
CVE Published:
6 December 2024

Summary

A vulnerability has been identified in SICK's AppManager, allowing unauthorized interactions with Lua applications. This issue permits unauthorized users to deploy, remove, start, reload, or stop applications without appropriate permissions. As a result, an attacker could potentially disrupt legitimate applications, leading to a denial of service (DoS) condition. Furthermore, this vulnerability enables the attacker to read and write files or to load malicious applications that exploit the full range of features available to legitimate users. Proper security measures must be taken to mitigate this risk.

Affected Version(s)

SICK InspectorP61x 0

SICK InspectorP62x 0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Manuel Stotz
Tobias Jaeger
.