Vulnerabilidades em SICK AG

114 resultados
Análise Vexday

O portfólio de vulnerabilidades da SICK AG reúne 112 CVEs catalogadas, com 14 classificadas como severidade crítica, mas nenhuma atualmente registrada no catálogo CISA KEV de exploração ativa — taxa abaixo da média geral do catálogo, o que sugere pressão ofensiva relativamente contida sobre os produtos da empresa. A ausência de PoCs públicas e de novas CVEs nos últimos 90 dias reforça um cenário de superfície de ataque estável no curto prazo. A falha mais comum é CWE-284 (controle de acesso impróprio), categoria que tende a ser crítica em ambientes de tecnologia operacional e dispositivos industriais, domínio típico da SICK AG. A CVE mais perigosa ativa, CVE-2023-23444, apresenta EPSS de 0,0117, indicando probabilidade de exploração baixa no momento, mas seu monitoramento contínuo é recomendado dado o contexto de infraestrutura industrial em que esses ativos costumam operar.

CVE-2025-49183HIGHUnencrypted communication (HTTP)EPSS 0.3%CVE-2023-31410CRITICALA remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TEPSS 0.3%CVE-2023-4420CRITICALA remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TEPSS 0.3%CVE-2025-49197MEDIUMDeprecated TLS version supportedEPSS 0.3%CVE-2026-22919LOWAn attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site scripting (XSS) attEPSS 0.3%CVE-2025-49189MEDIUMCookie missing HttpOnly flagEPSS 0.3%CVE-2025-9913MEDIUMCross Site Scripting: Session HijackingEPSS 0.3%CVE-2025-49185MEDIUMStored Cross-Site-ScriptEPSS 0.3%CVE-2025-49196MEDIUMDeprecated TLS version supportedEPSS 0.3%CVE-2026-80469HIGHCVE-2026-80469EPSS 0.2%CVE-2024-11075HIGHSICK Incoming Goods Suite privilege escalation vulnerabilityEPSS 0.2%CVE-2023-35699MEDIUMCleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device to disclose sensitiveEPSS 0.2%CVE-2026-1627MEDIUMAn attacker may exploit the use of outdated and weak MAC algorithms in the device’s SSH service to potentially compromise the integrity of tEPSS 0.2%CVE-2026-1626MEDIUMAn attacker may exploit the use of weak CBC-based cipher suites in the device’s SSH service to potentially observe or manipulate parts of thEPSS 0.2%