CVE-2023-23450
Last modified
CVE-2023-23450 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to use a password hash instead of an actual password to login to a valid user account via the REST interface.. EPSS estimates a 0.71% chance of exploitation in the next 30 days.
Description
Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to use a password hash instead of an actual password to login to a valid user account via the REST interface.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sick | Ftmg-Esd20axx Firmware | < 2.0 |
| Sick | Ftmg-Esd25axx Firmware | < 2.0 |
| Sick | Ftmg-Esn40sxx Firmware | < 2.0 |
| Sick | Ftmg-Esn50sxx Firmware | < 2.0 |
| Sick | Ftmg-Esr50sxx Firmware | < 2.0 |
| Sick | Ftmg-Esr40sxx Firmware | < 2.0 |
| Sick | Ftmg-Esd15axx Firmware | < 2.0 |
References
- https://sick.com/psirtVendor Advisory
- https://sick.com/psirtVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-23450?
How severe is CVE-2023-23450?
How do I fix CVE-2023-23450?
Are you affected by CVE-2023-23450?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
