sick
by SICK AG
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-8751 | Hig | 0.49 | 7.5 | 0.01 | Sep 12, 2024 | A vulnerability allows a remote unauthenticated attacker to modify the prod uct’s IP address over the Sopas ET interface. This can lead to a Denial of Service attack. | ||
| CVE-2026-22644 | Med | 0.34 | 5.3 | 0.00 | Jan 15, 2026 | Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer headers, which could allow an attacker to hijack the user's session and gain unauthorized access. | ||
| CVE-2026-22918 | Med | 0.28 | 4.3 | 0.00 | Jan 15, 2026 | An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted web pages, leading to the extraction of sensitive data. | ||
| CVE-2026-22915 | Med | 0.28 | 4.3 | 0.00 | Jan 15, 2026 | An attacker with low privileges may be able to read files from specific directories on the device, potentially exposing sensitive information. | ||
| CVE-2026-22913 | Med | 0.28 | 4.3 | 0.00 | Jan 15, 2026 | Improper handling of a URL parameter may allow attackers to execute code in a user's browser after login. This can lead to the extraction of sensitive data. |
- risk 0.49cvss 7.5epss 0.01
A vulnerability allows a remote unauthenticated attacker to modify the prod uct’s IP address over the Sopas ET interface. This can lead to a Denial of Service attack.
- risk 0.34cvss 5.3epss 0.00
Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer headers, which could allow an attacker to hijack the user's session and gain unauthorized access.
- risk 0.28cvss 4.3epss 0.00
An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted web pages, leading to the extraction of sensitive data.
- risk 0.28cvss 4.3epss 0.00
An attacker with low privileges may be able to read files from specific directories on the device, potentially exposing sensitive information.
- risk 0.28cvss 4.3epss 0.00
Improper handling of a URL parameter may allow attackers to execute code in a user's browser after login. This can lead to the extraction of sensitive data.