CVE-2023-35697: High severity SICK Icr890-4 Firmware vulnerability
Improper Restriction of Excessive Authentication Attempts in the SICK ICR890-4 could allow a remote attacker to brute-force user credentials.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SICK ICR890-4 firmwareto a version that resolves this vulnerability.Fixed in V2.5.0
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-35697.
What is the severity of CVE-2023-35697?
The severity of CVE-2023-35697 is high with a severity value of 7.
What is the affected software of CVE-2023-35697?
The affected software of CVE-2023-35697 is the SICK ICR890-4 firmware versions up to and excluding 2.5.0.
How can a remote attacker exploit CVE-2023-35697?
A remote attacker can exploit CVE-2023-35697 by brute-forcing user credentials.
Are there any references available for CVE-2023-35697?
Yes, references for CVE-2023-35697 are available at the following links: [Reference 1](https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.json), [Reference 2](https://sick.com/psirt), [Reference 3](https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.pdf).