SICK InspectorP61x, SICK InspectorP62x and SICK TiM3xx are vulnerable for remote code execution
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.8epss 1.1%
probabilidad de explotación
1.1%top 38% de las CVE
explotación observada
noninguna fuente lo reporta
Due to missing input validation during one step of the firmware update process, the product
is vulnerable to remote code execution. With network access and the user level ”Service”, an attacker
can execute arbitrary system commands in the root user’s contexts.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Productos afectados
SICK AG · SICK InspectorP61xSICK AG · SICK InspectorP62xSICK AG · TDC-X401GLSICK AG · TiM3xxReferencias
https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDFhttps://sick.com/psirthttps://www.cisa.gov/resources-tools/resources/ics-recommended-practiceshttps://www.first.org/cvss/calculator/3.1https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.jsonhttps://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.pdf