CRITICAL🇵🇱 Wersja polska

CVE-2023-31410

CVSS 9.8v3.1pub. 2023-06-19upd. 2024-11-21

A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK EventCam App. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive information. The attacker can exploit this weakness to eavesdrop on the communication between the EventCam App and the Client, and potentially manipulate the data being transmitted.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Sick Eventcam App

    APP
    Sick
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-31411CRITICAL9.8PL ✓same product

Brak uwierzytelnienia API w SICK EventCam App umożliwia przejęcie konfiguracji

CVE-2026-22907CRITICAL9.9PL ✓same vendor

Nieautoryzowany dostęp do systemu plików hosta w SICK TDC-X401GL

CVE-2026-22908CRITICAL9.1PL ✓same vendor

Brak walidacji obrazów kontenerów w SICK TDC-X401GL — pełny dostęp do systemu

CVE-2023-5288CRITICAL9.8PL ✓same vendor

Nieautoryzowany zdalny dostęp do urządzenia SICK SIM1012 — zmiana konfiguracji i upload firmware

CVE-2023-4420CRITICAL9.8PL ✓same vendor

Brak szyfrowania TLS w urządzeniach SICK LMS5xx — przechwycenie komunikacji