ZeroHour

CVE-2023-23445

CVSS 3.1
7.5 high
EPSS
<1%p49
Published
()
Modified
Description

Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to gain unauthorized access to data fields by using a therefore unpriviledged account via the REST interface.

Vendors
sick
Products
ftmg-esd20axx firmware, ftmg-esd25axx firmware, ftmg-esn40sxx firmware, ftmg-esn50sxx firmware, ftmg-esr50sxx firmware, ftmg-esr40sxx firmware, ftmg-esd15axx firmware
Weakness
CWE-284, CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.