First published: Mon Feb 20 2023(Updated: )
Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.
Credit: psirt@sick.de
Affected Software | Affected Version | How to fix |
---|---|---|
Sick Fx0-gent00010 Firmware | =3.04 | |
Sick Fx0-gent00010 Firmware | =3.05 | |
Sick Fx0-gent00010 | ||
Sick Fx0-gent00000 Firmware | =3.04 | |
Sick Fx0-gent00000 Firmware | =3.05 | |
SICK FX0-GENT00000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-23453 is critical with a severity value of 9.8.
CVE-2023-23453 affects SICK FX0-GENT v3 Firmware versions 3.04 and 3.05.
An unprivileged remote attacker can achieve arbitrary remote code execution by sending maliciously crafted RK512 commands to the listener on TCP port 9000.
There is no known fix for CVE-2023-23453 at the moment. It is recommended to follow the recommendations provided by the vendor or the security advisory.
You can find more information about CVE-2023-23453 on the official SICK website.