CVE-2023-23447
Last modified
CVE-2023-23447 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to influence the availability of the webserver by invocing several open file requests via the REST interface.. EPSS estimates a 1.12% chance of exploitation in the next 30 days.
Description
Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to influence the availability of the webserver by invocing several open file requests via the REST interface.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sick | Ftmg-Esd20axx Firmware | < 2.0 |
| Sick | Ftmg-Esd25axx Firmware | < 2.0 |
| Sick | Ftmg-Esn40sxx Firmware | < 2.0 |
| Sick | Ftmg-Esn50sxx Firmware | < 2.0 |
| Sick | Ftmg-Esr50sxx Firmware | < 2.0 |
| Sick | Ftmg-Esr40sxx Firmware | < 2.0 |
| Sick | Ftmg-Esd15axx Firmware | < 2.0 |
References
- https://sick.com/psirtVendor Advisory
- https://sick.com/psirtVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-23447?
How severe is CVE-2023-23447?
How do I fix CVE-2023-23447?
Are you affected by CVE-2023-23447?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
