First published: Mon May 15 2023(Updated: )
Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to gain unauthorized access to data fields by using a therefore unpriviledged account via the REST interface.
Credit: psirt@sick.de
Affected Software | Affected Version | How to fix |
---|---|---|
Sick Ftmg-esd20axx Firmware | <2.0 | |
Sick Ftmg-esd20axx | ||
Sick Ftmg-esd25axx Firmware | <2.0 | |
Sick Ftmg-esd25axx | ||
Sick Ftmg-esn40sxx Firmware | <2.0 | |
Sick Ftmg-esn40sxx | ||
Sick Ftmg-esn50sxx Firmware | <2.0 | |
Sick Ftmg-esn50sxx | ||
Sick Ftmg-esr50sxx Firmware | <2.0 | |
Sick Ftmg-esr50sxx | ||
Sick Ftmg-esr40sxx Firmware | <2.0 | |
Sick Ftmg-esr40sxx | ||
Sick Ftmg-esd15axx Firmware | <2.0 | |
Sick Ftmg-esd15axx |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23445 is an improper access control vulnerability in the SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, and 1122526 that allows an unprivileged remote attacker to gain unauthorized access to data fields via the REST interface.
The severity of CVE-2023-23445 is high, with a severity value of 7.5.
SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, and 1122526 are affected by CVE-2023-23445.
An attacker can exploit CVE-2023-23445 by using an unprivileged account to gain unauthorized access to data fields via the REST interface.
Yes, you can find references for CVE-2023-23445 at the following links: [Link 1](https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.json), [Link 2](https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf), [Link 3](https://sick.com/psirt).