CVE-2023-23452: Critical severity sick fx0-gpnt00000 vulnerability
Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-23452?
CVE-2023-23452 is a vulnerability that allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000 in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05.
How severe is CVE-2023-23452?
CVE-2023-23452 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2023-23452?
CVE-2023-23452 affects SICK FX0-GPNT v3 Firmware Version 3.04 and 3.05.
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-23452?
CVE-2023-23452 is associated with CWE-306, indicating that it is a missing authentication vulnerability.
How can I fix CVE-2023-23452?
To fix CVE-2023-23452, it is recommended to update the SICK FX0-GPNT v3 Firmware to a version that addresses the vulnerability.