First published: Mon Jul 10 2023(Updated: )
Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the FTP server from the response given during a failed login attempt.
Credit: psirt@sick.de psirt@sick.de
Affected Software | Affected Version | How to fix |
---|---|---|
Sick Icr890-4 Firmware | <2.5.0 | |
SICK ICR890-4 |
The recommended solution is to update the firmware to a version >= V2.5.0 as soon as possible.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35698 is a vulnerability in the SICK ICR890-4 that allows a remote attacker to identify valid usernames for the FTP server.
CVE-2023-35698 occurs due to observable response discrepancy in the SICK ICR890-4 during a failed login attempt.
The severity of CVE-2023-35698 is classified as medium (5.3).
The SICK ICR890-4 firmware versions up to 2.5.0 are affected by CVE-2023-35698.
To mitigate CVE-2023-35698, it is recommended to update the SICK ICR890-4 firmware to a version beyond 2.5.0.