DL100
by SICK AG
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-27595 | Cri | 0.64 | 9.8 | 0.01 | Mar 14, 2025 | The device uses a weak hashing alghorithm to create the password hash. Hence, a matching password can be easily calculated by an attacker. This impacts the security and the integrity of the device. | ||
| CVE-2025-27593 | Cri | 0.60 | 9.3 | 0.00 | Mar 14, 2025 | The product can be used to distribute malicious code using SDD Device Drivers due to missing download verification checks, leading to code execution on target systems. | ||
| CVE-2025-27594 | Hig | 0.49 | 7.5 | 0.00 | Mar 14, 2025 | The device uses an unencrypted, proprietary protocol for communication. Through this protocol, configuration data is transmitted and device authentication is performed. An attacker can thereby intercept the authentication hash and use it to log into the device using a… |
- risk 0.64cvss 9.8epss 0.01
The device uses a weak hashing alghorithm to create the password hash. Hence, a matching password can be easily calculated by an attacker. This impacts the security and the integrity of the device.
- risk 0.60cvss 9.3epss 0.00
The product can be used to distribute malicious code using SDD Device Drivers due to missing download verification checks, leading to code execution on target systems.
- risk 0.49cvss 7.5epss 0.00
The device uses an unencrypted, proprietary protocol for communication. Through this protocol, configuration data is transmitted and device authentication is performed. An attacker can thereby intercept the authentication hash and use it to log into the device using a…