First published: Mon Jul 10 2023(Updated: )
Cleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a remote attacker to gather sensitive information by intercepting network traffic that is not encrypted.
Credit: psirt@sick.de psirt@sick.de
Affected Software | Affected Version | How to fix |
---|---|---|
Sick Icr890-4 Firmware | <2.5.0 | |
SICK ICR890-4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3272 is a vulnerability in the SICK ICR890-4 firmware that allows a remote attacker to intercept unencrypted network traffic and gather sensitive information.
CVE-2023-3272 exposes SICK ICR890-4 firmware to the risk of cleartext transmission of sensitive information, enabling remote attackers to intercept unencrypted network traffic.
CVE-2023-3272 has a severity rating of 7.5, which is considered high.
To fix CVE-2023-3272, it is recommended to update the SICK ICR890-4 firmware to version 2.5.0 or higher, which provides encryption for network traffic.
More information about CVE-2023-3272 can be found at the following references: [Link 1](https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.json), [Link 2](https://sick.com/psirt), [Link 3](https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.pdf).