Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confidentiality.
The vulnerability mechanism involves lack of validation of transmitted container images — the device accepts and runs images without verifying their source or content. An attacker with administrative privileges (PR:H) can transmit a malicious container image over the network, which when executed gains access to system resources outside the container environment (S:C — scope change). The vulnerability is classified as CWE-266 (improper privilege management), suggesting that the containerized process may run with excessive privileges at the host level.
An attacker can gain full access to the device's operating system, resulting in complete breach of confidentiality, integrity, and availability — including the ability to take control of the industrial device.
Patches available from the manufacturer should be applied according to references — see document SCA-2026-0001 available at https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0001.pdf and contact SICK PSIRT at https://sick.com/psirt. It is also recommended to restrict network access to the device management interface and apply the principle of least privilege when configuring container environments.
SICK TDC-X401GL and SICK TDC-X401GL Firmware — specific versions indicated in manufacturer references (SCA-2026-0001)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HSick Tdc X401gl
HWSickall versionsSick Tdc X401gl Firmware
OSSick< 1.4.0
Related vulnerabilities
Nieautoryzowany dostęp do systemu plików hosta w SICK TDC-X401GL
The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasi...
Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or d...
Nieprawidłowa walidacja parametru logowania może umożliwić atakującym przekierowanie użytkowników na złośliwe ...
Pliki aktualizacji firmware mogą ujawnić skróty haseł kont systemowych, co może pozwolić atakującemu z dostępe...