Vulnerabilidades em SICK AG

113 resultados
Análise Vexday

O portfólio de vulnerabilidades da SICK AG reúne 112 CVEs catalogadas, com 14 classificadas como severidade crítica, mas nenhuma atualmente registrada no catálogo CISA KEV de exploração ativa — taxa abaixo da média geral do catálogo, o que sugere pressão ofensiva relativamente contida sobre os produtos da empresa. A ausência de PoCs públicas e de novas CVEs nos últimos 90 dias reforça um cenário de superfície de ataque estável no curto prazo. A falha mais comum é CWE-284 (controle de acesso impróprio), categoria que tende a ser crítica em ambientes de tecnologia operacional e dispositivos industriais, domínio típico da SICK AG. A CVE mais perigosa ativa, CVE-2023-23444, apresenta EPSS de 0,0117, indicando probabilidade de exploração baixa no momento, mas seu monitoramento contínuo é recomendado dado o contexto de infraestrutura industrial em que esses ativos costumam operar.

CVE-2023-23444HIGHMissing Authentication for Critical Function in SICK Flexi Classic and Flexi Soft Gateways with Partnumbers 1042193, 1042964, 1044078, 10440EPSS 1.2%CVE-2023-31409MEDIUMUncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 112252EPSS 1.1%CVE-2023-23447HIGHUncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 112252EPSS 1.1%CVE-2023-3273HIGHImproper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by chanEPSS 1.1%CVE-2024-10771HIGHSICK InspectorP61x, SICK InspectorP62x and SICK TiM3xx are vulnerable for remote code executionEPSS 1.1%CVE-2023-3270HIGHExposure of Sensitive Information to an Unauthorized Actor in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sEPSS 1.0%CVE-2023-35696HIGHUnauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the deEPSS 0.9%CVE-2024-8751HIGHCVE-2024-8751EPSS 0.9%CVE-2023-3271HIGHImproper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and downlEPSS 0.9%CVE-2023-31411CRITICALA remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication. ThEPSS 0.9%CVE-2023-35697MEDIUMImproper Restriction of Excessive Authentication Attempts in the SICK ICR890-4 could allow a remote attacker to brute-force user credentialsEPSS 0.9%CVE-2023-23446HIGHImproper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows aEPSS 0.9%CVE-2026-2331CRITICALCVE-2026-2331EPSS 0.9%CVE-2023-23448MEDIUMInclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116,EPSS 0.8%CVE-2023-35698MEDIUMObservable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the FTP server from the rEPSS 0.8%CVE-2023-23449MEDIUMObservable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 EPSS 0.8%CVE-2023-5246HIGHAuthentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073, 1127717, 1130282, 1044074, 1121597, 1099832, 1EPSS 0.8%CVE-2025-0593HIGHSICK Lector8xx and InspectorP8xx vulnerable for code executionEPSS 0.8%CVE-2024-10025CRITICALVulnerability in SICK CLV6xx, SICK Lector6xx and SICK RFx6xxEPSS 0.8%CVE-2023-43699HIGH Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU allows an unprivileged remote attacker to guess the passworEPSS 0.7%