First published: Mon Jul 10 2023(Updated: )
Unauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the device via HTTP requests.
Credit: psirt@sick.de psirt@sick.de
Affected Software | Affected Version | How to fix |
---|---|---|
Sick Icr890-4 Firmware | <2.5.0 | |
SICK ICR890-4 |
The recommended solution is to update the firmware to a version >= V2.5.0 as soon as possible.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The affected software versions of CVE-2023-35696 are up to and exclusive of version 2.5.0.
The severity of CVE-2023-35696 is high, with a severity value of 7.
An unauthenticated remote attacker can exploit CVE-2023-35696 by sending HTTP requests to unauthenticated endpoints, allowing them to retrieve sensitive information about the device.
Yes, SICK ICR890-4 is vulnerable to CVE-2023-35696.
You can find more information about CVE-2023-35696 at the following references: [Link 1](https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.json), [Link 2](https://sick.com/psirt), [Link 3](https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.pdf).