HIGH🇬🇧 English

CVE-2023-23444

CVSS 7.5v3.1pub. 2023-05-12upd. 2025-01-24

Missing Authentication for Critical Function in SICK Flexi Classic and Flexi Soft Gateways with Partnumbers 1042193, 1042964, 1044078, 1044072, 1044073, 1044074, 1099830, 1099832, 1127717, 1069070, 1112296, 1051432, 1102420, 1127487, 1121596, 1121597 allows an unauthenticated remote attacker to influence the availability of the device by changing the IP settings of the device via broadcasted UDP packets.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Sick Fx0 Gent00000

    HW
    Sick
    wszystkie wersje
  • Sick Fx0 Gent00000 Firmware

    OS
    Sick
    wszystkie wersje
  • Sick Fx0 Gent00010

    HW
    Sick
    wszystkie wersje
  • Sick Fx0 Gent00010 Firmware

    OS
    Sick
    wszystkie wersje
  • Sick Fx0 Gent00030

    HW
    Sick
    wszystkie wersje
  • Sick Fx0 Gent00030 Firmware

    OS
    Sick
    wszystkie wersje
  • Sick Fx0 Gmod00000

    HW
    Sick
    wszystkie wersje
  • Sick Fx0 Gmod00000 Firmware

    OS
    Sick
    wszystkie wersje
  • Sick Fx0 Gmod00010

    HW
    Sick
    wszystkie wersje
  • Sick Fx0 Gmod00010 Firmware

    OS
    Sick
    wszystkie wersje
  • Sick Fx0 Gpnt00000

    HW
    Sick
    wszystkie wersje
  • Sick Fx0 Gpnt00000 Firmware

    OS
    Sick
    wszystkie wersje
  • Sick Fx0 Gpnt00010

    HW
    Sick
    wszystkie wersje
  • Sick Fx0 Gpnt00010 Firmware

    OS
    Sick
    wszystkie wersje
  • Sick Fx0 Gpnt00030

    HW
    Sick
    wszystkie wersje
  • Sick Fx0 Gpnt00030 Firmware

    OS
    Sick
    wszystkie wersje
  • Sick Ue410 En1

    HW
    Sick
    wszystkie wersje
  • Sick Ue410 En1 Firmware

    OS
    Sick
    wszystkie wersje
  • Sick Ue410 En3

    HW
    Sick
    wszystkie wersje
  • Sick Ue410 En3 Firmware

    OS
    Sick
    wszystkie wersje
  • Sick Ue410 En4

    HW
    Sick
    wszystkie wersje
  • Sick Ue410 En4 Firmware

    OS
    Sick
    wszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2023-23451CRITICAL9.8PL ✓ten sam produkt

SICK Flexi Classic/Soft Gateways — domyślnie włączony Telnet bez hasła

CVE-2023-23452CRITICAL9.8PL ✓ten sam produkt

RCE w SICK FX0-GPNT v3 — brak uwierzytelnienia dla funkcji krytycznych

CVE-2023-23453CRITICAL9.8PL ✓ten sam produkt

Brak uwierzytelnienia w SICK FX0-GENT v3 umożliwia RCE przez port TCP 9000

CVE-2023-5246HIGH8.8ten sam produkt

Authentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073, 1127717, 1130282...

CVE-2019-14753HIGH7.5ten sam produkt

SICK FX0-GPNT00000 and FX0-GENT00000 devices through 3.4.0 have a Buffer Overflow