First published: Wed Apr 19 2023(Updated: )
The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN1 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN3S04 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN4 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK FX0-GENT00000 FLEXISOFT EIP GATEW. with serial number <=2311xxxx with Firmware <=V2.11.0, SICK FX0-GMOD00000 FLEXISOFT MOD GATEW. with serial number <=2311xxxx with Firmware <=V2.11.0, SICK FX0-GPNT00000 FLEXISOFT PNET GATEW. with serial number <=2311xxxx with Firmware <=V2.12.0, SICK FX0-GENT00030 FLEXISOFT EIP GATEW.V2 with serial number <=2311xxxx all Firmware versions, SICK FX0-GPNT00030 FLEXISOFT PNET GATEW.V2 with serial number <=2311xxxx all Firmware versions and SICK FX0-GMOD00010 FLEXISOFT MOD GW with serial number <=2311xxxx with Firmware <=V2.11.0 all have Telnet enabled by factory default. No password is set in the default configuration.
Credit: psirt@sick.de psirt@sick.de
Affected Software | Affected Version | How to fix |
---|---|---|
Sick Ue410-en3 Firmware | ||
SICK UE410-EN3 | ||
Sick Ue410-en1 Firmware | ||
SICK UE410-EN1 | ||
Sick Ue410-en3s04 Firmware | ||
SICK UE410-EN3S04 | ||
Sick Ue410-en4 Firmware | ||
SICK UE410-EN4 | ||
Sick Fx0-gent00000 Firmware | <=2.11.0 | |
SICK FX0-GENT00000 | ||
Sick Fx0-gmod00000 Firmware | <=2.11.0 | |
SICK FX0-GMOD00000 | ||
Sick Fx0-gpnt00000 Firmware | <=2.12.0 | |
SICK FX0-GPNT00000 | ||
Sick Fx0-gent00030 Firmware | ||
SICK FX0-GENT00030 | ||
Sick Fx0-gpnt00030 Firmware | ||
SICK FX0-GPNT00030 | ||
Sick Fx0-gmod00010 Firmware | <=2.11.0 | |
SICK FX0-GMOD00010 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2023-23451.
The severity of CVE-2023-23451 is critical.
All firmware versions of SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx, SICK UE410-EN1 FLEXI ETHERNET GATEW. with serial number <=2311xxxx, and SICK UE410-EN3S04 FLEXI ETHERNET GATEW. with serial number <=2311xxxx are affected.
To fix CVE-2023-23451, it is recommended to apply the latest firmware update provided by SICK and follow any additional instructions or recommendations from the vendor.
You can find more information about CVE-2023-23451 on the SICK product security website at https://sick.com/psirt.