CVE-2024-10025: Vulnerability in SICK CLV6xx, SICK Lector6xx and SICK RFx6xx
A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By exploiting these plaintext credentials, an attacker can log into affected SICK products as an “Authorized Client” if the customer has not changed the default password.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10025?
CVE-2024-10025 is considered a high severity vulnerability due to the potential exposure of default passwords that could allow unauthorized access.
How do I fix CVE-2024-10025?
To remediate CVE-2024-10025, ensure that all default passwords are changed immediately to strong, unique passwords for affected SICK products.
Which products are affected by CVE-2024-10025?
CVE-2024-10025 affects the SICK CLV6xx, Lector6xx, and RFx6xx product lines.
What type of information can be exposed by CVE-2024-10025?
CVE-2024-10025 can expose default passwords stored in plain text within the .sdd file, which can lead to unauthorized access.
What should I do if I cannot change the passwords for CVE-2024-10025?
If you are unable to change the passwords, it is critical to isolate the affected systems from the network until a proper fix can be applied.