CVE-2023-35699: Medium severity SICK Icr890-4 Firmware vulnerability
Cleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device to disclose sensitive information by accessing a SD card.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-35699.
What is the title of this vulnerability?
The title of this vulnerability is Cleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device to disclose sensitive information by accessing a SD card.
What is the severity level of CVE-2023-35699?
CVE-2023-35699 has a severity level of medium, with a severity value of 4.
How can an unauthenticated attacker exploit this vulnerability?
An unauthenticated attacker with local access to the device can exploit this vulnerability by accessing a SD card on the SICK ICR890-4, leading to the disclosure of sensitive information.
Is the SICK ICR890-4 vulnerable to this issue?
Yes, the SICK ICR890-4 firmware versions up to but excluding 2.5.0 are vulnerable to this issue.