CVE-2023-43697: Medium severity sick apu0200 firmware vulnerability
Modification of Assumed-Immutable Data (MAID) in RDT400 in SICK APU allows an unprivileged remote attacker to make the site unable to load necessary strings via changing file paths using HTTP requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-43697?
CVE-2023-43697 is a vulnerability in the SICK APU that allows an unprivileged remote attacker to make the site unable to load necessary strings by changing file paths using HTTP requests.
How does CVE-2023-43697 affect SICK APU?
CVE-2023-43697 affects SICK APU version up to 4.0.0.6 firmware by allowing an unprivileged remote attacker to modify assumed-immutable data and disrupt the loading of necessary strings.
What is the severity of CVE-2023-43697?
CVE-2023-43697 has a severity rating of 6.5 (medium) according to the Common Vulnerability Scoring System (CVSS).
How can I fix CVE-2023-43697?
To fix CVE-2023-43697, it is recommended to update the SICK APU firmware to version 4.0.0.7 or higher, which addresses the vulnerability.
Where can I find more information about CVE-2023-43697?
More information about CVE-2023-43697 can be found on the SICK website: https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.pdf