CVE-2023-23450: Critical severity SICK Ftmg-esd20axx Firmware vulnerability
Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to use a password hash instead of an actual password to login to a valid user account via the REST interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23450?
The severity of CVE-2023-23450 is critical with a score of 9.8.
How does CVE-2023-23450 affect SICK FTMg AIR FLOW SENSOR?
CVE-2023-23450 allows an unprivileged remote attacker to login to a valid user account using a password hash instead of an actual password.
Which versions of SICK FTMg AIR FLOW SENSOR firmware are affected by CVE-2023-23450?
SICK FTMg AIR FLOW SENSOR firmware versions up to but excluding 2.0 are affected by CVE-2023-23450.
How can I fix CVE-2023-23450?
To fix CVE-2023-23450, users should update to a version of SICK FTMg AIR FLOW SENSOR firmware that is higher than 2.0.
Where can I find more information about CVE-2023-23450?
More information about CVE-2023-23450 can be found at the following references: [Link 1](https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.json), [Link 2](https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf), [Link 3](https://sick.com/psirt).