CVE-2023-3272: High severity SICK Icr890-4 Firmware vulnerability
Cleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a remote attacker to gather sensitive information by intercepting network traffic that is not encrypted.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3272?
CVE-2023-3272 is a vulnerability in the SICK ICR890-4 firmware that allows a remote attacker to intercept unencrypted network traffic and gather sensitive information.
How does CVE-2023-3272 impact SICK ICR890-4 firmware?
CVE-2023-3272 exposes SICK ICR890-4 firmware to the risk of cleartext transmission of sensitive information, enabling remote attackers to intercept unencrypted network traffic.
What is the severity of CVE-2023-3272?
CVE-2023-3272 has a severity rating of 7.5, which is considered high.
How can I fix CVE-2023-3272 in SICK ICR890-4 firmware?
To fix CVE-2023-3272, it is recommended to update the SICK ICR890-4 firmware to version 2.5.0 or higher, which provides encryption for network traffic.
Where can I find more information about CVE-2023-3272?
More information about CVE-2023-3272 can be found at the following references: [Link 1](https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.json), [Link 2](https://sick.com/psirt), [Link 3](https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.pdf).