CRITICAL🇵🇱 Wersja polska

CVE-2026-22908

CVSS 9.1v3.1pub. 2026-01-15upd. 2026-01-23

Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confidentiality.

🤖 AI Analysis
How it works

The vulnerability mechanism involves lack of validation of transmitted container images — the device accepts and runs images without verifying their source or content. An attacker with administrative privileges (PR:H) can transmit a malicious container image over the network, which when executed gains access to system resources outside the container environment (S:C — scope change). The vulnerability is classified as CWE-266 (improper privilege management), suggesting that the containerized process may run with excessive privileges at the host level.

Impact

An attacker can gain full access to the device's operating system, resulting in complete breach of confidentiality, integrity, and availability — including the ability to take control of the industrial device.

Mitigation & patch

Patches available from the manufacturer should be applied according to references — see document SCA-2026-0001 available at https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0001.pdf and contact SICK PSIRT at https://sick.com/psirt. It is also recommended to restrict network access to the device management interface and apply the principle of least privilege when configuring container environments.

Who is affected

SICK TDC-X401GL and SICK TDC-X401GL Firmware — specific versions indicated in manufacturer references (SCA-2026-0001)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Sick Tdc X401gl

    HW
    Sick
    all versions
  • Sick Tdc X401gl Firmware

    OS
    Sick
    < 1.4.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
CWE
References

Related vulnerabilities

CVE-2026-22907CRITICAL9.9PL ✓same product

Nieautoryzowany dostęp do systemu plików hosta w SICK TDC-X401GL

CVE-2026-22910HIGH7.5same product

The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasi...

CVE-2026-22909HIGH7.5same product

Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or d...

CVE-2026-22912MEDIUM4.3same product

Nieprawidłowa walidacja parametru logowania może umożliwić atakującym przekierowanie użytkowników na złośliwe ...

CVE-2026-22911MEDIUM5.3same product

Pliki aktualizacji firmware mogą ujawnić skróty haseł kont systemowych, co może pozwolić atakującemu z dostępe...