Show filters
80 Total Results
Displaying 31-40 of 80
Sort by:
Attacker Value
Unknown

CVE-2023-3271

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endpoints.
Attacker Value
Unknown

CVE-2023-3270

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
Exposure of Sensitive Information to an Unauthorized Actor in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the system.
Attacker Value
Unknown

CVE-2023-35699

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
Cleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device to disclose sensitive information by accessing a SD card.
Attacker Value
Unknown

CVE-2023-35698

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the FTP server from the response given during a failed login attempt.
Attacker Value
Unknown

CVE-2023-35697

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
Improper Restriction of Excessive Authentication Attempts in the SICK ICR890-4 could allow a remote attacker to brute-force user credentials.
Attacker Value
Unknown

CVE-2023-35696

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
Unauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the device via HTTP requests.
Attacker Value
Unknown

CVE-2023-31411

Disclosure Date: June 19, 2023 (last updated October 08, 2023)
A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication. The lack of authentication in the API allows the attacker to potentially compromise the functionality of the EventCam App.
Attacker Value
Unknown

CVE-2023-31410

Disclosure Date: June 19, 2023 (last updated October 08, 2023)
A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK EventCam App. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive information. The attacker can exploit this weakness to eavesdrop on the communication between the EventCam App and the Client, and potentially manipulate the data being transmitted.
Attacker Value
Unknown

CVE-2023-31409

Disclosure Date: May 15, 2023 (last updated October 08, 2023)
Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an remote attacker to influence the availability of the webserver by invocing a Slowloris style attack via HTTP requests.
Attacker Value
Unknown

CVE-2023-31408

Disclosure Date: May 15, 2023 (last updated October 08, 2023)
Cleartext Storage of Sensitive Information in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to potentially steal user credentials that are stored in the user’s browsers local storage via cross-site-scripting attacks.