First published: Mon May 15 2023(Updated: )
Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis of source code.
Credit: psirt@sick.de
Affected Software | Affected Version | How to fix |
---|---|---|
Sick Ftmg-esd20axx Firmware | <2.0 | |
Sick Ftmg-esd20axx | ||
Sick Ftmg-esd25axx Firmware | <2.0 | |
Sick Ftmg-esd25axx | ||
Sick Ftmg-esn40sxx Firmware | <2.0 | |
Sick Ftmg-esn40sxx | ||
Sick Ftmg-esn50sxx Firmware | <2.0 | |
Sick Ftmg-esn50sxx | ||
Sick Ftmg-esr50sxx Firmware | <2.0 | |
Sick Ftmg-esr50sxx | ||
Sick Ftmg-esr40sxx Firmware | <2.0 | |
Sick Ftmg-esr40sxx | ||
Sick Ftmg-esd15axx Firmware | <2.0 | |
Sick Ftmg-esd15axx |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23448 is a vulnerability that allows a remote attacker to gain information about valid usernames through the analysis of source code in the SICK FTMg AIR FLOW SENSOR.
The severity of CVE-2023-23448 is medium with a CVSS score of 5.3.
The SICK Ftmg-esd20axx Firmware version up to 2.0 is affected.
A remote attacker can exploit CVE-2023-23448 by analyzing the source code of the SICK FTMg AIR FLOW SENSOR to gain information about valid usernames.
No, other SICK FTMg sensors are not vulnerable to CVE-2023-23448.