First published: Mon Feb 20 2023(Updated: )
Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.
Credit: psirt@sick.de
Affected Software | Affected Version | How to fix |
---|---|---|
Sick Fx0-gpnt00000 Firmware | =3.04 | |
Sick Fx0-gpnt00000 Firmware | =3.05 | |
SICK FX0-GPNT00000 | ||
Sick Fx0-gpnt00010 Firmware | =3.04 | |
Sick Fx0-gpnt00010 Firmware | =3.05 | |
Sick Fx0-gpnt00010 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23452 is a vulnerability that allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000 in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05.
CVE-2023-23452 has a severity rating of 9.8 (Critical).
CVE-2023-23452 affects SICK FX0-GPNT v3 Firmware Version 3.04 and 3.05.
CVE-2023-23452 is associated with CWE-306, indicating that it is a missing authentication vulnerability.
To fix CVE-2023-23452, it is recommended to update the SICK FX0-GPNT v3 Firmware to a version that addresses the vulnerability.