First published: Mon May 15 2023(Updated: )
Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to gain unauthorized access to data fields by using a therefore unpriviledged account via the REST interface.
Credit: psirt@sick.de
Affected Software | Affected Version | How to fix |
---|---|---|
Sick FTG-ESD20AXX | <2.0 | |
Sick FTG-ESD20AXX | ||
Sick Ftmg-esd25axx Firmware | <2.0 | |
Sick Ftmg-esd25axx Firmware | ||
Sick Ftmg-esn40sxx | <2.0 | |
Sick FTG-MG-ESN40SXX | ||
Sick FTG-MG-ESN50SXX | <2.0 | |
Sick FTG-MG-ESN50SXX | ||
Sick FTMG-ESR50SXX | <2.0 | |
Sick FTMG-ESR50SXX | ||
Sick FTMG-ESR40SXX | <2.0 | |
Sick FTMG-ESR40SXX | ||
Sick FTMG-ESD15AXX | <2.0 | |
Sick FTMG-ESD15AXX |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23445 is an improper access control vulnerability in the SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, and 1122526 that allows an unprivileged remote attacker to gain unauthorized access to data fields via the REST interface.
The severity of CVE-2023-23445 is high, with a severity value of 7.5.
SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, and 1122526 are affected by CVE-2023-23445.
An attacker can exploit CVE-2023-23445 by using an unprivileged account to gain unauthorized access to data fields via the REST interface.
Yes, you can find references for CVE-2023-23445 at the following links: [Link 1](https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.json), [Link 2](https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf), [Link 3](https://sick.com/psirt).