VYPR

Vendor CVEs

SICK AG

All CVEs

155 total · sorted by risk
  • CVE-2026-2331CriMar 6, 2026
    risk 0.64cvss 9.8epss 0.01

    An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature,…

  • CVE-2026-22907CriJan 15, 2026
    risk 0.64cvss 9.9epss 0.00

    An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.

  • CVE-2025-27595CriMar 14, 2025
    risk 0.64cvss 9.8epss 0.01

    The device uses a weak hashing alghorithm to create the password hash. Hence, a matching password can be easily calculated by an attacker. This impacts the security and the integrity of the device.

  • CVE-2025-0867CriFeb 14, 2025
    risk 0.64cvss 9.9epss 0.01

    The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that the system can startup on its own, the credentials of the administrator were stored. Consequently, the EPC2 user can execute any command with administrative…

  • CVE-2023-5288CriSep 29, 2023
    risk 0.64cvss 9.8epss 0.01

    A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings. The adversary may also reset the SIM and in the worst case upload a new firmware version to the device.

  • CVE-2023-4420CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.00

    A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK LMS5xx. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive…

  • CVE-2023-4419CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    The LMS5xx uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure settings and /or disrupt the functionality of the device.

  • CVE-2023-31411CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication. The lack of authentication in the API allows the attacker to potentially compromise the functionality of the EventCam App.

  • CVE-2023-31410CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.00

    A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK EventCam App. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive…

  • CVE-2023-23451CriApr 19, 2023
    risk 0.64cvss 9.8epss 0.01

    The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN1 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN3S04 FLEXI ETHERNET GATEW. with serial…

  • CVE-2023-23453CriFeb 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.

  • CVE-2023-23452CriFeb 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.

  • CVE-2022-47377CriDec 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an…

  • CVE-2022-27586CriNov 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Password recovery vulnerability in SICK SIM1004 Partnumber 1098148 with firmware version <2.0.0 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase…

  • CVE-2022-27585CriNov 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Password recovery vulnerability in SICK SIM1000 FX Partnumber 1097816 and 1097817 with firmware version <1.6.0 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads…

  • CVE-2022-27584CriNov 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Password recovery vulnerability in SICK SIM2000ST Partnumber 1080579 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase in their privileges on the…

  • CVE-2022-27582CriNov 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Password recovery vulnerability in SICK SIM4000 (PPC) Partnumber 1078787 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase in their privileges on…

  • CVE-2020-2076CriJul 29, 2020
    risk 0.64cvss 9.8epss 0.01

    SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with the REST API. An attacker can send unauthorized requests, bypass current authentication controls presented by the application and could…

  • CVE-2019-10979CriJul 1, 2019
    risk 0.64cvss 9.8epss 0.03

    SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password.

  • CVE-2026-2330CriMar 6, 2026
    risk 0.61cvss 9.4epss 0.01

    An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain directories intended for internal testing were not covered by the whitelist and are accessible without authentication. An…

  • CVE-2025-27593CriMar 14, 2025
    risk 0.60cvss 9.3epss 0.00

    The product can be used to distribute malicious code using SDD Device Drivers due to missing download verification checks, leading to code execution on target systems.

  • CVE-2026-22908CriJan 15, 2026
    risk 0.59cvss 9.1epss 0.01

    Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confidentiality.

  • CVE-2024-10773CriDec 6, 2024
    risk 0.59cvss 9.0epss 0.01

    The product is vulnerable to pass-the-hash attacks in combination with hardcoded credentials of hidden user levels. This means that an attacker can log in with the hidden user levels and gain full access to the device.

  • CVE-2024-10025CriOct 17, 2024
    risk 0.59cvss 9.1epss 0.01

    A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By exploiting these plaintext credentials, an attacker can log into affected SICK products as an “Authorized Client” if the customer has not changed the…

  • CVE-2022-27583CriOct 31, 2022
    risk 0.59cvss 9.1epss 0.01

    A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2 running an affected firmware version to potentially impact the availability of the FlexiCompact.

  • CVE-2022-27577CriApr 11, 2022
    risk 0.59cvss 9.1epss 0.01

    The vulnerability in the MSC800 in all versions before 4.15 allows for an attacker to predict the TCP initial sequence number. When the TCP sequence is predictable, an attacker can send packets that are forged to appear to come from a trusted computer. These forged packets could…

  • CVE-2025-49199HigJun 12, 2025
    risk 0.57cvss 8.8epss 0.00

    The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it. This allows the attacker to disrupt the application by configuring the services in a way that they are unable to run, …

  • CVE-2025-0592HigFeb 14, 2025
    risk 0.57cvss 8.8epss 0.00

    The vulnerability may allow a remote low priviledged attacker to run arbitrary shell commands by manipulating the firmware file and uploading it to the device.

  • CVE-2024-10772HigDec 6, 2024
    risk 0.57cvss 8.8epss 0.00

    Since the firmware update is not validated, an attacker can install modified firmware on the device. This has a high impact on the availabilty, integrity and confidentiality up to the complete compromise of the device.

  • CVE-2024-11075HigNov 19, 2024
    risk 0.57cvss 8.8epss 0.00

    A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escalation to the administrative level due to the usage of component vendor Docker images running with root permissions. Exploiting…

  • CVE-2023-5246HigOct 23, 2023
    risk 0.57cvss 8.8epss 0.01

    Authentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073, 1127717, 1130282, 1044074, 1121597, 1099832, 1051432, 1127487, 1069070, 1112296, 1044072, 1121596, 1099830 allows an unauthenticated remote attacker to potentially impact the…

  • CVE-2025-49181HigJun 12, 2025
    risk 0.56cvss 8.6epss 0.00

    Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive information. An attacker could also send HTTP POST requests to modify the log files’ root path as well as the TCP ports the service is running on, leading to a…

  • CVE-2023-3270HigJul 10, 2023
    risk 0.56cvss 8.6epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the system.

  • CVE-2021-32498HigDec 17, 2021
    risk 0.56cvss 8.6epss 0.01

    SICK SOPAS ET before version 4.8.0 allows attackers to manipulate the pathname of the emulator and use path traversal to run an arbitrary executable located on the host system. When the user starts the emulator from SOPAS ET the corresponding executable will be started instead…

  • CVE-2021-32497HigDec 17, 2021
    risk 0.56cvss 8.6epss 0.01

    SICK SOPAS ET before version 4.8.0 allows attackers to wrap any executable file into an SDD and provide this to a SOPAS ET user. When a user starts the emulator the executable is run without further checks.

  • CVE-2024-10776HigDec 6, 2024
    risk 0.53cvss 8.2epss 0.00

    Lua apps can be deployed, removed, started, reloaded or stopped without authorization via AppManager. This allows an attacker to remove legitimate apps creating a DoS attack, read and write files or load apps that use all features of the product available to a customer.

  • CVE-2023-43696HigOct 9, 2023
    risk 0.53cvss 8.2epss 0.01

    Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous access to the FTP server.

  • CVE-2023-3271HigJul 10, 2023
    risk 0.53cvss 8.2epss 0.01

    Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endpoints.

  • CVE-2022-27580HigJul 19, 2022
    risk 0.51cvss 7.8epss 0.00

    A deserialization vulnerability in a .NET framework class used and not properly checked by Safety Designer all versions up to and including 1.11.0 allows an attacker to craft malicious project files. Opening/importing such a malicious project file would execute arbitrary code…

  • CVE-2022-27579HigJul 19, 2022
    risk 0.51cvss 7.8epss 0.00

    A deserialization vulnerability in a .NET framework class used and not properly checked by Flexi Soft Designer in all versions up to and including 1.9.4 SP1 allows an attacker to craft malicious project files. Opening/importing such a malicious project file would execute…

  • CVE-2022-27578HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.00

    An attacker can perform a privilege escalation through the SICK OEE if the application is installed in a directory where non authenticated or low privilege users can modify its content.

  • CVE-2023-43700HigOct 9, 2023
    risk 0.50cvss 7.7epss 0.01

    Missing Authorization in RDT400 in SICK APU allows an unprivileged remote attacker to modify data via HTTP requests that no not require authentication.

  • CVE-2026-22910HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.00

    The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the integrity of the system.

  • CVE-2026-22909HigJan 15, 2026
    risk 0.49cvss 7.5epss 0.01

    Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potentially disrupting system operations.

  • CVE-2025-59461HigOct 27, 2025
    risk 0.49cvss 7.6epss 0.00

    A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services.

  • CVE-2025-59460HigOct 27, 2025
    risk 0.49cvss 7.5epss 0.00

    The system is deployed in its default state, with configuration settings that do not comply with the latest best practices for restricting access. This increases the risk of unauthorised connections.

  • CVE-2025-27461HigJul 3, 2025
    risk 0.49cvss 7.6epss 0.00

    During startup, the device automatically logs in the EPC2 Windows user without requesting a password.

  • CVE-2025-27460HigJul 3, 2025
    risk 0.49cvss 7.6epss 0.00

    The hard drives of the device are not encrypted using a full volume encryption feature such as BitLocker. This allows an attacker with physical access to the device to use an alternative operating system to interact with the hard drives, completely circumventing the Windows…

  • CVE-2025-27456HigJul 3, 2025
    risk 0.49cvss 7.5epss 0.01

    The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

  • CVE-2025-27449HigJul 3, 2025
    risk 0.49cvss 7.5epss 0.01

    The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

Page 1 of 4