First published: Mon May 15 2023(Updated: )
Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an remote attacker to influence the availability of the webserver by invocing a Slowloris style attack via HTTP requests.
Credit: psirt@sick.de
Affected Software | Affected Version | How to fix |
---|---|---|
Sick Ftmg-esd20axx Firmware | <2.0 | |
Sick Ftmg-esd20axx | ||
Sick Ftmg-esd25axx Firmware | <2.0 | |
Sick Ftmg-esd25axx | ||
Sick Ftmg-esn40sxx Firmware | <2.0 | |
Sick Ftmg-esn40sxx | ||
Sick Ftmg-esn50sxx Firmware | <2.0 | |
Sick Ftmg-esn50sxx | ||
Sick Ftmg-esr50sxx Firmware | <2.0 | |
Sick Ftmg-esr50sxx | ||
Sick Ftmg-esr40sxx Firmware | <2.0 | |
Sick Ftmg-esr40sxx | ||
Sick Ftmg-esd15axx Firmware | <2.0 | |
Sick Ftmg-esd15axx |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-31409 is high with a severity value of 7.5.
CVE-2023-31409 allows a remote attacker to influence the availability of the webserver by invoking a Slowloris style attack via HTTP requests on SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526.
CVE-2023-31409 affects Sick Ftmg-esd20axx Firmware versions up to but not including 2.0, Sick Ftmg-esd25axx Firmware versions up to but not including 2.0, Sick Ftmg-esn40sxx Firmware versions up to but not including 2.0, Sick Ftmg-esn50sxx Firmware versions up to but not including 2.0, Sick Ftmg-esr50sxx Firmware versions up to but not including 2.0, Sick Ftmg-esr40sxx Firmware versions up to but not including 2.0, Sick Ftmg-esd15axx Firmware versions up to but not including 2.0.
To fix CVE-2023-31409, it is recommended to update to a version of Sick Ftmg-esd20axx Firmware, Sick Ftmg-esd25axx Firmware, Sick Ftmg-esn40sxx Firmware, Sick Ftmg-esn50sxx Firmware, Sick Ftmg-esr50sxx Firmware, Sick Ftmg-esr40sxx Firmware, or Sick Ftmg-esd15axx Firmware that is higher than 2.0.
More information about CVE-2023-31409 can be found at the following references: [CVE-2023-31409 JSON](https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.json), [CVE-2023-31409 PDF](https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf), [SICK website](https://sick.com/psirt).