First published: Mon Jun 19 2023(Updated: )
A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication. The lack of authentication in the API allows the attacker to potentially compromise the functionality of the EventCam App.
Credit: psirt@sick.de
Affected Software | Affected Version | How to fix |
---|---|---|
Sick Sick Eventcam App |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-31411.
The severity level of CVE-2023-31411 is critical, with a score of 9.8.
The affected software is the Sick EventCam App.
CVE-2023-31411 allows a remote unprivileged attacker to modify and access configuration settings on the EventCam App, potentially compromising its functionality.
Yes, you can find references for CVE-2023-31411 at the following links: [Reference 1](https://sick.com/.well-known/csaf/white/2023/sca-2023-0005.json), [Reference 2](https://sick.com/.well-known/csaf/white/2023/sca-2023-0005.pdf), [Reference 3](https://sick.com/psirt).