CYBERSECURITY BY SICK
by SICK AG
CVEs (10)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-10773 | Cri | 0.59 | 9.0 | 0.01 | Dec 6, 2024 | The product is vulnerable to pass-the-hash attacks in combination with hardcoded credentials of hidden user levels. This means that an attacker can log in with the hidden user levels and gain full access to the device. | ||
| CVE-2025-0592 | Hig | 0.57 | 8.8 | 0.00 | Feb 14, 2025 | The vulnerability may allow a remote low priviledged attacker to run arbitrary shell commands by manipulating the firmware file and uploading it to the device. | ||
| CVE-2024-10772 | Hig | 0.57 | 8.8 | 0.00 | Dec 6, 2024 | Since the firmware update is not validated, an attacker can install modified firmware on the device. This has a high impact on the availabilty, integrity and confidentiality up to the complete compromise of the device. | ||
| CVE-2025-49181 | Hig | 0.56 | 8.6 | 0.00 | Jun 12, 2025 | Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive information. An attacker could also send HTTP POST requests to modify the log files’ root path as well as the TCP ports the service is running on, leading to a… | ||
| CVE-2025-49182 | Hig | 0.49 | 7.5 | 0.00 | Jun 12, 2025 | Files in the source code contain login credentials for the admin user and the property configuration password, allowing an attacker to get full access to the application. | ||
| CVE-2025-32470 | Hig | 0.49 | 7.5 | 0.01 | Apr 28, 2025 | A remote unauthenticated attacker may be able to change the IP adress of the device, and therefore affecting the availability of the device. | ||
| CVE-2025-49200 | Med | 0.42 | 6.5 | 0.00 | Jun 12, 2025 | The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downloading and decompressing the backup files. | ||
| CVE-2025-49189 | Med | 0.34 | 5.3 | 0.00 | Jun 12, 2025 | The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag to false can lead to a higher possibility of Cross-Side-Scripting attacks which target the stored cookies. | ||
| CVE-2025-49190 | Med | 0.28 | 4.3 | 0.00 | Jun 12, 2025 | The application is vulnerable to Server-Side Request Forgery (SSRF). An endpoint can be used to send server internal requests to other ports. | ||
| CVE-2025-49193 | Med | 0.27 | 4.2 | 0.00 | Jun 12, 2025 | The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code… |
- risk 0.59cvss 9.0epss 0.01
The product is vulnerable to pass-the-hash attacks in combination with hardcoded credentials of hidden user levels. This means that an attacker can log in with the hidden user levels and gain full access to the device.
- risk 0.57cvss 8.8epss 0.00
The vulnerability may allow a remote low priviledged attacker to run arbitrary shell commands by manipulating the firmware file and uploading it to the device.
- risk 0.57cvss 8.8epss 0.00
Since the firmware update is not validated, an attacker can install modified firmware on the device. This has a high impact on the availabilty, integrity and confidentiality up to the complete compromise of the device.
- risk 0.56cvss 8.6epss 0.00
Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive information. An attacker could also send HTTP POST requests to modify the log files’ root path as well as the TCP ports the service is running on, leading to a…
- risk 0.49cvss 7.5epss 0.00
Files in the source code contain login credentials for the admin user and the property configuration password, allowing an attacker to get full access to the application.
- risk 0.49cvss 7.5epss 0.01
A remote unauthenticated attacker may be able to change the IP adress of the device, and therefore affecting the availability of the device.
- risk 0.42cvss 6.5epss 0.00
The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downloading and decompressing the backup files.
- risk 0.34cvss 5.3epss 0.00
The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag to false can lead to a higher possibility of Cross-Side-Scripting attacks which target the stored cookies.
- risk 0.28cvss 4.3epss 0.00
The application is vulnerable to Server-Side Request Forgery (SSRF). An endpoint can be used to send server internal requests to other ports.
- risk 0.27cvss 4.2epss 0.00
The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code…