CVE-2023-35696: High severity SICK Icr890-4 Firmware vulnerability
Unauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the device via HTTP requests.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SICK ICR890-4 firmwareto a version that resolves this vulnerability.Fixed in V2.5.0
Event History
Frequently Asked Questions
What are the affected software versions of CVE-2023-35696?
The affected software versions of CVE-2023-35696 are up to and exclusive of version 2.5.0.
What is the severity of CVE-2023-35696?
The severity of CVE-2023-35696 is high, with a severity value of 7.
How can an attacker exploit CVE-2023-35696?
An unauthenticated remote attacker can exploit CVE-2023-35696 by sending HTTP requests to unauthenticated endpoints, allowing them to retrieve sensitive information about the device.
Is SICK ICR890-4 vulnerable to CVE-2023-35696?
Yes, SICK ICR890-4 is vulnerable to CVE-2023-35696.
Where can I find more information about CVE-2023-35696?
You can find more information about CVE-2023-35696 at the following references: [Link 1](https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.json), [Link 2](https://sick.com/psirt), [Link 3](https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.pdf).