First published: Mon May 15 2023(Updated: )
Cleartext Storage of Sensitive Information in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to potentially steal user credentials that are stored in the user’s browsers local storage via cross-site-scripting attacks.
Credit: psirt@sick.de
Affected Software | Affected Version | How to fix |
---|---|---|
Sick Ftmg-esd20axx Firmware | <2.0 | |
Sick Ftmg-esd20axx | ||
Sick Ftmg-esd25axx Firmware | <2.0 | |
Sick Ftmg-esd25axx | ||
Sick Ftmg-esn40sxx Firmware | <2.0 | |
Sick Ftmg-esn40sxx | ||
Sick Ftmg-esn50sxx Firmware | <2.0 | |
Sick Ftmg-esn50sxx | ||
Sick Ftmg-esr50sxx Firmware | <2.0 | |
Sick Ftmg-esr50sxx | ||
Sick Ftmg-esr40sxx Firmware | <2.0 | |
Sick Ftmg-esr40sxx | ||
Sick Ftmg-esd15axx Firmware | <2.0 | |
Sick Ftmg-esd15axx |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-31408 is a vulnerability that allows a remote attacker to potentially steal user credentials stored in the user's browser local storage via cross-site scripting attacks on SICK FTMg AIR FLOW SENSOR.
CVE-2023-31408 has a severity rating of 7.5 (High).
CVE-2023-31408 affects SICK FTMg AIR FLOW SENSOR firmware versions up to but not including 2.0.
To fix CVE-2023-31408, it is recommended to update the SICK FTMg AIR FLOW SENSOR firmware to version 2.0 or later.
You can find more information about CVE-2023-31408 on the official SICK website's PSIRT page and the provided references.