First published: Mon Jul 10 2023(Updated: )
Improper Restriction of Excessive Authentication Attempts in the SICK ICR890-4 could allow a remote attacker to brute-force user credentials.
Credit: psirt@sick.de psirt@sick.de
Affected Software | Affected Version | How to fix |
---|---|---|
Sick Icr890-4 Firmware | <2.5.0 | |
SICK ICR890-4 |
The recommended solution is to update the firmware to a version >= V2.5.0 as soon as possible.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2023-35697.
The severity of CVE-2023-35697 is high with a severity value of 7.
The affected software of CVE-2023-35697 is the SICK ICR890-4 firmware versions up to and excluding 2.5.0.
A remote attacker can exploit CVE-2023-35697 by brute-forcing user credentials.
Yes, references for CVE-2023-35697 are available at the following links: [Reference 1](https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.json), [Reference 2](https://sick.com/psirt), [Reference 3](https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.pdf).