First published: Mon May 15 2023(Updated: )
Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames by analyzing challenge responses from the server via the REST interface.
Credit: psirt@sick.de
Affected Software | Affected Version | How to fix |
---|---|---|
Sick Ftmg-esd20axx Firmware | <2.0 | |
Sick Ftmg-esd20axx | ||
Sick Ftmg-esd25axx Firmware | <2.0 | |
Sick Ftmg-esd25axx | ||
Sick Ftmg-esn40sxx Firmware | <2.0 | |
Sick Ftmg-esn40sxx | ||
Sick Ftmg-esn50sxx Firmware | <2.0 | |
Sick Ftmg-esn50sxx | ||
Sick Ftmg-esr50sxx Firmware | <2.0 | |
Sick Ftmg-esr50sxx | ||
Sick Ftmg-esr40sxx Firmware | <2.0 | |
Sick Ftmg-esr40sxx | ||
Sick Ftmg-esd15axx Firmware | <2.0 | |
Sick Ftmg-esd15axx |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-23449 is medium with a severity value of 5.3.
CVE-2023-23449 allows a remote attacker to gain information about valid usernames by analyzing challenge responses from the server via the REST interface.
Yes, Sick Ftmg-esd20axx Firmware is vulnerable to CVE-2023-23449.
There is currently no fix available for CVE-2023-23449. It is recommended to follow the vendor's instructions and recommendations.
More information about CVE-2023-23449 can be found at the following references: [Link 1](https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.json), [Link 2](https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf), [Link 3](https://sick.com/psirt)