First published: Mon Jul 10 2023(Updated: )
Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endpoints.
Credit: psirt@sick.de psirt@sick.de
Affected Software | Affected Version | How to fix |
---|---|---|
Sick Icr890-4 Firmware | <2.5.0 | |
SICK ICR890-4 |
The recommended solution is to update the firmware to a version >= V2.5.0 as soon as possible.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3271 is a vulnerability in the SICK ICR890-4 firmware that allows an unauthenticated remote attacker to gather information about the system and download data via the REST API.
The severity of CVE-2023-3271 is high with a CVSS score of 7.5.
CVE-2023-3271 allows an unauthenticated remote attacker to access unauthenticated endpoints in the SICK ICR890-4 firmware, thereby gathering information and downloading data via the REST API.
Yes, the SICK ICR890-4 firmware version 2.5.0 is affected by CVE-2023-3271.
To fix the CVE-2023-3271 vulnerability, it is recommended to update the SICK ICR890-4 firmware to a version above 2.5.0 or apply any available patches or fixes provided by the vendor.