Vulnerabilidades em SICK AG

114 resultados
Análise Vexday

O portfólio de vulnerabilidades da SICK AG reúne 112 CVEs catalogadas, com 14 classificadas como severidade crítica, mas nenhuma atualmente registrada no catálogo CISA KEV de exploração ativa — taxa abaixo da média geral do catálogo, o que sugere pressão ofensiva relativamente contida sobre os produtos da empresa. A ausência de PoCs públicas e de novas CVEs nos últimos 90 dias reforça um cenário de superfície de ataque estável no curto prazo. A falha mais comum é CWE-284 (controle de acesso impróprio), categoria que tende a ser crítica em ambientes de tecnologia operacional e dispositivos industriais, domínio típico da SICK AG. A CVE mais perigosa ativa, CVE-2023-23444, apresenta EPSS de 0,0117, indicando probabilidade de exploração baixa no momento, mas seu monitoramento contínuo é recomendado dado o contexto de infraestrutura industrial em que esses ativos costumam operar.

CVE-2025-58580MEDIUMInjection via log fileEPSS 0.4%CVE-2025-58583MEDIUMUser EnumerationEPSS 0.4%CVE-2025-58586MEDIUMUser Enumeration by excessive error outputEPSS 0.4%CVE-2025-58589LOWInformation Disclosure Through StacktraceEPSS 0.4%CVE-2025-32471LOWReuse of saltEPSS 0.4%CVE-2025-0592HIGHSICK Lector8xx and InspectorP8xx vulnerable for code executionEPSS 0.4%CVE-2023-5100MEDIUM Cleartext Transmission of Sensitive Information in RDT400 in SICK APU allows an unprivileged remote attacker to retrieve potentially sensitEPSS 0.4%CVE-2025-49191MEDIUMDashboards and iFrames can link malicious web contentEPSS 0.3%CVE-2025-49190MEDIUMServer-Side Request ForgeryEPSS 0.3%CVE-2024-10772HIGHSICK InspectorP61x and SICK InspectorP62x are vulnerable for firmware modificationEPSS 0.3%CVE-2025-58581MEDIUMInformation Disclosure Through Stacktrace-/MQTT/Config/changeAllEPSS 0.3%CVE-2025-49199HIGHBackup files can be modified and uploadedEPSS 0.3%CVE-2025-49192MEDIUMClickjackingEPSS 0.3%CVE-2026-22918MEDIUMAn attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously craEPSS 0.3%CVE-2025-9914MEDIUMThe credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to gain unEPSS 0.3%CVE-2025-58578LOWUnlimited user creation by authorized usersEPSS 0.3%CVE-2025-59459MEDIUMDenial-of-service (DoS) via resource consumptionEPSS 0.3%CVE-2025-49194HIGHUnencrypted communicationEPSS 0.3%CVE-2026-22914MEDIUMAn attacker with limited permissions may still be able to write files to specific locations on the device, potentially leading to system manEPSS 0.3%CVE-2025-49193MEDIUMMissing HTTP Security HeadersEPSS 0.3%