Vulnerabilidades em SICK AG

114 resultados
Análise Vexday

O portfólio de vulnerabilidades da SICK AG reúne 112 CVEs catalogadas, com 14 classificadas como severidade crítica, mas nenhuma atualmente registrada no catálogo CISA KEV de exploração ativa — taxa abaixo da média geral do catálogo, o que sugere pressão ofensiva relativamente contida sobre os produtos da empresa. A ausência de PoCs públicas e de novas CVEs nos últimos 90 dias reforça um cenário de superfície de ataque estável no curto prazo. A falha mais comum é CWE-284 (controle de acesso impróprio), categoria que tende a ser crítica em ambientes de tecnologia operacional e dispositivos industriais, domínio típico da SICK AG. A CVE mais perigosa ativa, CVE-2023-23444, apresenta EPSS de 0,0117, indicando probabilidade de exploração baixa no momento, mas seu monitoramento contínuo é recomendado dado o contexto de infraestrutura industrial em que esses ativos costumam operar.

CVE-2025-27594HIGHUnencrypted transmission of password hashEPSS 0.4%CVE-2025-49188MEDIUMSensitive Data in URLEPSS 0.4%CVE-2023-31408MEDIUMCleartext Storage of Sensitive Information in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 112252EPSS 0.4%CVE-2025-58585MEDIUMSensitive Information Disclosure Through Missing AuthenticationEPSS 0.4%CVE-2023-31412HIGHThe LMS5xx uses weak hash generation methods, resulting in the creation of insecure hashs. If an attacker manages to retrieve the hash, it cEPSS 0.4%CVE-2026-22646MEDIUMCertain error messages returned by the application expose internal system details that should not be visible to end users, providing attackeEPSS 0.4%CVE-2026-22915MEDIUMAn attacker with low privileges may be able to read files from specific directories on the device, potentially exposing sensitive informatioEPSS 0.4%CVE-2024-11022MEDIUMSICK InspectorP61x and SICK InspectorP62x are vulnerable for a replay attackEPSS 0.4%CVE-2025-27593CRITICALRCE due to Device DriverEPSS 0.4%CVE-2025-49187MEDIUMUser enumerationEPSS 0.4%CVE-2025-58579MEDIUMUsername Disclosure Through Missing AuthenticationEPSS 0.4%CVE-2025-49181HIGHConfigurations endpoint does not require authorizationEPSS 0.4%CVE-2025-59460HIGHUnsecure access configurationEPSS 0.4%CVE-2026-22913MEDIUMImproper handling of a URL parameter may allow attackers to execute code in a user's browser after login. This can lead to the extraction ofEPSS 0.4%CVE-2025-58584MEDIUMPlain Text Transmission of Username and Password in the URLEPSS 0.4%CVE-2025-59463MEDIUMDenial-of-service (DoS) via chunk size mismatchEPSS 0.4%CVE-2025-49198LOWPoor quality of randomness in authorization tokensEPSS 0.4%CVE-2026-22916MEDIUMAn attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without proper restrictionsEPSS 0.4%CVE-2025-49186MEDIUMNo brute-force protectionEPSS 0.4%CVE-2026-22912MEDIUMImproper validation of a login parameter may allow attackers to redirect users to malicious websites after authentication. This can lead to EPSS 0.4%