ZeroHour

CVE-2026-80469

Driver signature verification bypass enables user-assisted RCE in SICK product

CVSS 3.1
8.3 high
EPSS
Published
()
Modified
AI analysis

SICK AG (whose PSIRT is the assigned CNA) has disclosed a flaw in which device driver packages are not properly verified, classified as improper verification of a cryptographic signature (CWE-347). An attacker can prepare a malicious device driver package that bypasses the driver verification mechanism; the attack vector is network-based, but user interaction is required, meaning a user must be persuaded to upload or install the attacker-supplied package. If the malicious package is accepted, attacker-controlled code runs on the target system, yielding arbitrary code execution with high impact on confidentiality, integrity, and availability, and the changed-scope CVSS metric indicates the compromise extends beyond the vulnerable component itself. No privileges are required and attack complexity is high, so successful exploitation depends on favorable conditions and user cooperation rather than a reliable one-shot attack. The affected product name and version ranges were not included in the available data, and no public proof-of-concept, CISA KEV listing, or in-the-wild exploitation has been reported.

What to do: Check SICK's official PSIRT advisory (sick.com PSIRT page / [email protected]) for CVE-2026-80469 to identify the affected product and version range, and apply the vendor patch or updated driver-verification fix as soon as it is published. Until then, only install SICK device driver packages obtained directly from official SICK channels and verify digital signatures before installing. Because user interaction is required, warn staff not to install driver packages received via email, chat, or download links.

Affected
SICK AG
Estimated exposure
unknown (affected product name and install base not disclosed in available data) — No affected product name, version range, or public install/exposure counts were provided, leaving no defensible basis for an order-of-magnitude estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of attacker-controlled code. User interaction is required.

Weakness
CWE-347
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.