VYPR
Vendor

SICK AG

Products
210
CVEs
155
Across products
244
Status
Private

Products

210
View all 210 products →

Recent CVEs

155
View all 155 CVEs →
  • CVE-2026-2331CriMar 6, 2026
    risk 0.64cvss 9.8epss 0.01

    An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature,…

  • CVE-2026-22907CriJan 15, 2026
    risk 0.64cvss 9.9epss 0.00

    An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.

  • CVE-2025-27595CriMar 14, 2025
    risk 0.64cvss 9.8epss 0.01

    The device uses a weak hashing alghorithm to create the password hash. Hence, a matching password can be easily calculated by an attacker. This impacts the security and the integrity of the device.

  • CVE-2025-0867CriFeb 14, 2025
    risk 0.64cvss 9.9epss 0.01

    The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that the system can startup on its own, the credentials of the administrator were stored. Consequently, the EPC2 user can execute any command with administrative…

  • CVE-2023-5288CriSep 29, 2023
    risk 0.64cvss 9.8epss 0.01

    A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings. The adversary may also reset the SIM and in the worst case upload a new firmware version to the device.

  • CVE-2023-4420CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.00

    A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK LMS5xx. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive…

  • CVE-2023-4419CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    The LMS5xx uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure settings and /or disrupt the functionality of the device.

  • CVE-2023-31411CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication. The lack of authentication in the API allows the attacker to potentially compromise the functionality of the EventCam App.

  • CVE-2023-31410CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.00

    A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK EventCam App. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive…

  • CVE-2023-23451CriApr 19, 2023
    risk 0.64cvss 9.8epss 0.01

    The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN1 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN3S04 FLEXI ETHERNET GATEW. with serial…

  • CVE-2023-23453CriFeb 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.

  • CVE-2023-23452CriFeb 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.

  • CVE-2022-47377CriDec 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an…

  • CVE-2022-27586CriNov 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Password recovery vulnerability in SICK SIM1004 Partnumber 1098148 with firmware version <2.0.0 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase…

  • CVE-2022-27585CriNov 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Password recovery vulnerability in SICK SIM1000 FX Partnumber 1097816 and 1097817 with firmware version <1.6.0 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads…

  • CVE-2022-27584CriNov 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Password recovery vulnerability in SICK SIM2000ST Partnumber 1080579 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase in their privileges on the…

  • CVE-2022-27582CriNov 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Password recovery vulnerability in SICK SIM4000 (PPC) Partnumber 1078787 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase in their privileges on…

  • CVE-2020-2076CriJul 29, 2020
    risk 0.64cvss 9.8epss 0.01

    SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with the REST API. An attacker can send unauthorized requests, bypass current authentication controls presented by the application and could…

  • CVE-2019-10979CriJul 1, 2019
    risk 0.64cvss 9.8epss 0.03

    SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password.

  • CVE-2026-2330CriMar 6, 2026
    risk 0.61cvss 9.4epss 0.01

    An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain directories intended for internal testing were not covered by the whitelist and are accessible without authentication. An…