ZeroHour

CVE-2023-23446

CVSS 3.1
7.5 high
EPSS
<1%p57
Published
()
Modified
Description

Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to download files by using a therefore unpriviledged account via the REST interface.

Vendors
sick
Products
ftmg-esd20axx firmware, ftmg-esd25axx firmware, ftmg-esn40sxx firmware, ftmg-esn50sxx firmware, ftmg-esr50sxx firmware, ftmg-esr40sxx firmware, ftmg-esd15axx firmware
Weakness
CWE-284, CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.