First published: Mon Aug 31 2020(Updated: )
Platform mechanism AutoIP allows remote attackers to reboot the device via a crafted packet in SICK AG solutions Bulkscan LMS111, Bulkscan LMS511, CLV62x – CLV65x, ICR890-3, LMS10x, LMS11x, LMS15x, LMS12x, LMS13x, LMS14x, LMS5xx, LMS53x, MSC800, RFH.
Credit: psirt@sick.de
Affected Software | Affected Version | How to fix |
---|---|---|
SICK LMS111 | <1.04 | |
SICK LMS111 Firmware | ||
Sick LMS511 | <2.30 | |
Sick LMS | ||
Sick CLV620 | ||
Sick CLV620 Firmware | ||
Sick CLV622 | ||
Sick CLV622 Firmware | ||
Sick CLV621 | ||
Sick CLV621 Firmware | ||
Sick ICR890-3 Firmware | ||
Sick ICR890-3 Firmware | ||
SICK MSC800 | <4.10 | |
SICK MSC800 | ||
Sick Rfh | ||
Sick Rfh Firmware | ||
Sick CLV650 | ||
Sick CLV650 | ||
Sick CLV651 Firmware | ||
Sick CLV651 Firmware | ||
SICK CLV631 | ||
Sick CLV631 Firmware | ||
Sick CLV630 Firmware | ||
Sick CLV630 Firmware | ||
Sick CLV632 | ||
Sick CLV632 Firmware | ||
Sick CLV640 Firmware | ||
Sick CLV640 Firmware | ||
Sick CLV642 | ||
Sick CLV642 | ||
Sick LMS100 | <2.0 | |
Sick LMS | ||
Sick Lms101 Firmware | <2.0 | |
Sick Lms101 Firmware | ||
SICK LMS111 | <2.0 | |
Sick LMS153 | <2.0 | |
Sick LMS | ||
Sick Lms151 | <2.0 | |
Sick LMS | ||
Sick LMS | <2.10 | |
Sick Lms133 Firmware | ||
Sick LMS142 Firmware | <2.10 | |
Sick LMS142 Firmware | ||
Sick LMS | <2.10 | |
Sick LMS143 Firmware | ||
Sick LMS | <2.10 | |
Sick LMS131 Firmware | ||
Sick LMS121 | <2.10 | |
Sick LMS | ||
Sick LMS123 | <2.10 | |
Sick LMS123 Firmware | ||
Sick LMS122 Firmware | <2.10 | |
Sick LMS122 Firmware | ||
Sick LMS141 | <2.10 | |
Sick LMS | ||
Sick LMS511 | ||
Sick LMS | ||
Sick LMS531 Firmware | ||
Sick Lms500 Firmware | ||
Sick Lms500 Firmware | ||
Sick ICR890-3.5 Firmware | ||
Sick ICR890-3.5 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-2075 is a vulnerability in the platform mechanism AutoIP that allows remote attackers to reboot the device via a crafted packet in SICK AG solutions Bulkscan LMS111, Bulkscan LMS511, CLV62x – CLV65x, ICR890-3, LMS10x, LMS11x, LMS15x, LMS12x, LMS13x, LMS14x, LMS5xx, LMS53x, MSC800, RFH.
CVE-2020-2075 has a severity rating of 7.5, which is considered high.
CVE-2020-2075 affects SICK AG solutions Bulkscan LMS111, Bulkscan LMS511, CLV62x – CLV65x, ICR890-3, LMS10x, LMS11x, LMS15x, LMS12x, LMS13x, LMS14x, LMS5xx, LMS53x, MSC800, and RFH.
To fix CVE-2020-2075, it is recommended to apply the latest firmware update provided by SICK AG.
More information about CVE-2020-2075 can be found on the SICK AG Product Security Incident Response Team (PSIRT) advisory page: [link](https://www.sick.com/de/en/service-and-support/the-sick-product-security-incident-response-team-sick-psirt/w/psirt/#advisories)