CVE-2023-43696: Malicious File Upload
Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous access to the FTP server.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-43696?
CVE-2023-43696 is a vulnerability in the SICK APU software that allows an unprivileged remote attacker to download and upload arbitrary files via anonymous access to the FTP server.
What is the severity of CVE-2023-43696?
The severity of CVE-2023-43696 is rated as critical with a CVSS score of 9.8.
How does CVE-2023-43696 impact SICK APU?
CVE-2023-43696 allows an unprivileged remote attacker to gain unauthorized access to the FTP server and upload/download arbitrary files, potentially leading to further exploitation and unauthorized access to the system.
How can I fix CVE-2023-43696?
To fix CVE-2023-43696, it is recommended to update the SICK APU software to version 4.0.0.6 or higher.
Where can I find more information about CVE-2023-43696?
More information about CVE-2023-43696 can be found at the following references: [link1], [link2], [link3].