CVE-2023-3273: High severity SICK Icr890-4 Firmware vulnerability
Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by changing settings of the device such as the IP address based on missing access control.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-3273.
What is the title of this vulnerability?
The title of this vulnerability is 'Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device'.
What is the severity level of CVE-2023-3273?
The severity level of CVE-2023-3273 is high with a score of 7.5.
Which software is affected by this vulnerability?
The SICK ICR890-4 firmware up to version 2.5.0 is affected by this vulnerability.
How can an unauthenticated remote attacker exploit CVE-2023-3273?
An unauthenticated remote attacker can exploit CVE-2023-3273 by changing settings of the SICK ICR890-4 device, such as the IP address, due to missing access control.