First published: Tue Jul 19 2022(Updated: )
Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users only. A malicious attacker could use this sensitive information’s to launch further attacks on the system.
Credit: psirt@sick.de
Affected Software | Affected Version | How to fix |
---|---|---|
Sick Ftmg Firmware | <2.8 | |
Sick Ftmg |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32504 is classified as a medium severity vulnerability due to its potential to allow unauthorized access to sensitive information.
To fix CVE-2021-32504, ensure that sensitive web URLs are restricted to authenticated maintenance users only.
CVE-2021-32504 affects Sick FTMG firmware versions prior to 2.8.
An attacker could exploit CVE-2021-32504 to gain unauthorized access to sensitive information, potentially leading to further system attacks.
Yes, users should upgrade to Sick FTMG firmware version 2.8 or later to mitigate CVE-2021-32504.