CVE-2021-32503: Medium severity sick ftmc firmware vulnerability
Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users only. A malicious attacker could use this sensitive information’s to launch further attacks on the system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-32503?
CVE-2021-32503 is a vulnerability that allows unauthenticated users to access sensitive web URLs through a GET request.
Who is affected by CVE-2021-32503?
The vulnerability affects Sick Ftmg Firmware versions up to and including 2.8.
How can unauthenticated users exploit CVE-2021-32503?
Unauthenticated users can exploit the vulnerability by sending GET requests to sensitive web URLs that should be restricted to maintenance users only.
What is the severity of CVE-2021-32503?
The severity of CVE-2021-32503 is medium with a CVSS score of 4.9.
How can I fix CVE-2021-32503?
To fix CVE-2021-32503, restrict access to sensitive web URLs to maintenance users only and ensure that authentication is required for accessing them.