Vulnerabilidades em SICK AG

114 resultados
Análise Vexday

O portfólio de vulnerabilidades da SICK AG reúne 112 CVEs catalogadas, com 14 classificadas como severidade crítica, mas nenhuma atualmente registrada no catálogo CISA KEV de exploração ativa — taxa abaixo da média geral do catálogo, o que sugere pressão ofensiva relativamente contida sobre os produtos da empresa. A ausência de PoCs públicas e de novas CVEs nos últimos 90 dias reforça um cenário de superfície de ataque estável no curto prazo. A falha mais comum é CWE-284 (controle de acesso impróprio), categoria que tende a ser crítica em ambientes de tecnologia operacional e dispositivos industriais, domínio típico da SICK AG. A CVE mais perigosa ativa, CVE-2023-23444, apresenta EPSS de 0,0117, indicando probabilidade de exploração baixa no momento, mas seu monitoramento contínuo é recomendado dado o contexto de infraestrutura industrial em que esses ativos costumam operar.

CVE-2025-49182HIGHCredential disclosureEPSS 0.6%CVE-2026-22644MEDIUMCertain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxEPSS 0.5%CVE-2025-58591MEDIUMPath TraversalEPSS 0.5%CVE-2025-58590MEDIUMPath traversalEPSS 0.5%CVE-2025-27595CRITICALWeak hashing alghrythmEPSS 0.5%CVE-2026-22911MEDIUMFirmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover credentials and gain unEPSS 0.5%CVE-2025-49195MEDIUMNo protection against brute-force attacksEPSS 0.5%CVE-2025-59462MEDIUMDenial-of-service (DoS) via delayed or missing client responseEPSS 0.5%CVE-2024-10776HIGHSICK InspectorP61x and SICK InspectorP62x: missing authenticationEPSS 0.5%CVE-2025-58587MEDIUMImproper Restriction of Excessive Authentication AttemptsEPSS 0.5%CVE-2025-49184HIGHInformation disclosure to unauthorized userEPSS 0.5%CVE-2026-11841CRITICALCVE-2026-11841EPSS 0.5%CVE-2026-22910HIGHThe device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized acEPSS 0.5%CVE-2023-43698HIGH Improper Neutralization of Input During Web Page Generation (’Cross-site Scripting’) in RDT400 in SICK APU allows an unprivileged remote atEPSS 0.5%CVE-2025-49200MEDIUMUnencrypted backup contains sensitive informationEPSS 0.5%CVE-2025-59461HIGHAPI does not require authenticationEPSS 0.5%CVE-2024-10774HIGHSICK InspectorP61x and SICK InspectorP62x have unauthenticated CROWN APIsEPSS 0.5%CVE-2026-22645MEDIUMThe application discloses all used components, versions and license information to unauthenticated actors, giving attackers the opportunity EPSS 0.5%CVE-2023-5103MEDIUMImproper Restriction of Rendered UI Layers or Frames in RDT400 in SICK APU allows an unprivileged remote attacker to potentially reveal sensEPSS 0.5%CVE-2026-22907CRITICALAn attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.EPSS 0.4%