Vendor CVEs
SICK AG
All CVEs
155 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-11022 | Med | 0.36 | 5.6 | 0.00 | Dec 6, 2024 | The authentication process to the web server uses a challenge response procedure which inludes the nonce and additional information. This challenge can be used several times for login and is therefore vulnerable for a replay attack. | ||
| CVE-2023-35697 | Med | 0.35 | 5.3 | 0.01 | Jul 10, 2023 | Improper Restriction of Excessive Authentication Attempts in the SICK ICR890-4 could allow a remote attacker to brute-force user credentials. | ||
| CVE-2023-31409 | Med | 0.35 | 5.3 | 0.01 | May 15, 2023 | Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an remote attacker to influence the availability of the webserver by invocing a Slowloris style attack via HTTP requests. | ||
| CVE-2023-23449 | Med | 0.35 | 5.3 | 0.01 | May 15, 2023 | Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames by analyzing challenge responses from the server via the REST interface. | ||
| CVE-2023-23448 | Med | 0.35 | 5.3 | 0.01 | May 15, 2023 | Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis of source code. | ||
| CVE-2026-22645 | Med | 0.34 | 5.3 | 0.00 | Jan 15, 2026 | The application discloses all used components, versions and license information to unauthenticated actors, giving attackers the opportunity to target known security vulnerabilities of used components. | ||
| CVE-2026-22644 | Med | 0.34 | 5.3 | 0.01 | Jan 15, 2026 | Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer headers, which could allow an attacker to hijack the user's session and gain unauthorized access. | ||
| CVE-2026-22911 | Med | 0.34 | 5.3 | 0.00 | Jan 15, 2026 | Firmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover credentials and gain unauthorized access to the device. | ||
| CVE-2025-58586 | Med | 0.34 | 5.3 | 0.00 | Oct 6, 2025 | For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one. | ||
| CVE-2025-58585 | Med | 0.34 | 5.3 | 0.00 | Oct 6, 2025 | Multiple endpoints with sensitive information do not require authentication, making the application susceptible to information gathering. | ||
| CVE-2025-58584 | Med | 0.34 | 5.3 | 0.00 | Oct 6, 2025 | In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk that this sensitive data will be disclosed… | ||
| CVE-2025-58583 | Med | 0.34 | 5.3 | 0.00 | Oct 6, 2025 | The application provides access to a login protected H2 database for caching purposes. The username is prefilled. | ||
| CVE-2025-58582 | Med | 0.34 | 5.3 | 0.01 | Oct 6, 2025 | If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated and it’s possible to send giant payloads which are then logged. | ||
| CVE-2025-58579 | Med | 0.34 | 5.3 | 0.00 | Oct 6, 2025 | Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making the application vulnerable for user enumeration. | ||
| CVE-2025-27452 | Med | 0.34 | 5.3 | 0.00 | Jul 3, 2025 | The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure. There are modules activated that are not required for the operation of the FNADE4 web application. The functionality of the some modules pose a risk to the… | ||
| CVE-2025-27451 | Med | 0.34 | 5.3 | 0.00 | Jul 3, 2025 | For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one. | ||
| CVE-2025-49195 | Med | 0.34 | 5.3 | 0.00 | Jun 12, 2025 | The FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker to brute-force user passwords and potentially compromising the FTP server. | ||
| CVE-2025-49189 | Med | 0.34 | 5.3 | 0.00 | Jun 12, 2025 | The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag to false can lead to a higher possibility of Cross-Side-Scripting attacks which target the stored cookies. | ||
| CVE-2025-49188 | Med | 0.34 | 5.3 | 0.00 | Jun 12, 2025 | The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering. | ||
| CVE-2025-49187 | Med | 0.34 | 5.3 | 0.00 | Jun 12, 2025 | For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one. | ||
| CVE-2025-49186 | Med | 0.34 | 5.3 | 0.00 | Jun 12, 2025 | The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks. | ||
| CVE-2025-32472 | Med | 0.34 | 5.3 | 0.01 | Apr 28, 2025 | The multiScan and picoScan are vulnerable to a denial-of-service (DoS) attack. A remote attacker can exploit this vulnerability by conducting a Slowloris-type attack, causing the web page to become unresponsive. | ||
| CVE-2023-5102 | Med | 0.34 | 5.3 | 0.01 | Oct 9, 2023 | Insufficient Control Flow Management in RDT400 in SICK APU allows an unprivileged remote attacker to potentially enable hidden functionality via HTTP requests. | ||
| CVE-2023-5101 | Med | 0.34 | 5.3 | 0.01 | Oct 9, 2023 | Files or Directories Accessible to External Parties in RDT400 in SICK APU allows an unprivileged remote attacker to download various files from the server via HTTP requests. | ||
| CVE-2023-35699 | Med | 0.34 | 5.3 | 0.00 | Jul 10, 2023 | Cleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device to disclose sensitive information by accessing a SD card. | ||
| CVE-2023-35698 | Med | 0.34 | 5.3 | 0.01 | Jul 10, 2023 | Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the FTP server from the response given during a failed login attempt. | ||
| CVE-2023-31408 | Med | 0.34 | 5.3 | 0.00 | May 15, 2023 | Cleartext Storage of Sensitive Information in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to potentially steal user credentials that are stored in the user’s browsers local storage via… | ||
| CVE-2021-32504 | Med | 0.34 | 5.3 | 0.01 | Jul 19, 2022 | Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users only. A malicious attacker could use this sensitive information’s to launch further attacks on the system. | ||
| CVE-2021-32496 | Med | 0.34 | 5.3 | 0.00 | Jun 28, 2021 | SICK Visionary-S CX up version 5.21.2.29154R are vulnerable to an Inadequate Encryption Strength vulnerability concerning the internal SSH interface solely used by SICK for recovering returned devices. The use of weak ciphers make it easier for an attacker to break the security… | ||
| CVE-2021-32503 | Med | 0.32 | 4.9 | 0.01 | Apr 1, 2022 | Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users only. A malicious attacker could use this sensitive information’s to launch further attacks on the system. | ||
| CVE-2025-49191 | Med | 0.31 | 4.8 | 0.00 | Jun 12, 2025 | Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it possible to attack other users that access the dashboard by including malicious code. The attack is only possible if the attacker… | ||
| CVE-2025-9913 | Med | 0.29 | 4.5 | 0.00 | Oct 6, 2025 | JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking. | ||
| CVE-2025-27459 | Med | 0.29 | 4.4 | 0.00 | Jul 3, 2025 | The VNC application stores its passwords encrypted within the registry but uses DES for encryption. As DES is broken, the original passwords can be recovered. | ||
| CVE-2026-22646 | Med | 0.28 | 4.3 | 0.00 | Jan 15, 2026 | Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance information (like file paths, database errors, or software versions) that can be used to map the… | ||
| CVE-2026-22918 | Med | 0.28 | 4.3 | 0.00 | Jan 15, 2026 | An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted web pages, leading to the extraction of sensitive data. | ||
| CVE-2026-22917 | Med | 0.28 | 4.3 | 0.01 | Jan 15, 2026 | Improper input handling in a system endpoint may allow attackers to overload resources, causing a denial of service. | ||
| CVE-2026-22916 | Med | 0.28 | 4.3 | 0.00 | Jan 15, 2026 | An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without proper restrictions, potentially leading to service disruption or loss of configuration. | ||
| CVE-2026-22915 | Med | 0.28 | 4.3 | 0.00 | Jan 15, 2026 | An attacker with low privileges may be able to read files from specific directories on the device, potentially exposing sensitive information. | ||
| CVE-2026-22914 | Med | 0.28 | 4.3 | 0.00 | Jan 15, 2026 | An attacker with limited permissions may still be able to write files to specific locations on the device, potentially leading to system manipulation. | ||
| CVE-2026-22913 | Med | 0.28 | 4.3 | 0.00 | Jan 15, 2026 | Improper handling of a URL parameter may allow attackers to execute code in a user's browser after login. This can lead to the extraction of sensitive data. | ||
| CVE-2026-22912 | Med | 0.28 | 4.3 | 0.00 | Jan 15, 2026 | Improper validation of a login parameter may allow attackers to redirect users to malicious websites after authentication. This can lead to various risk including stealing credentials from unsuspecting users. | ||
| CVE-2025-59463 | Med | 0.28 | 4.3 | 0.00 | Oct 27, 2025 | An attacker may cause chunk-size mismatches that block file transfers and prevent subsequent transfers. | ||
| CVE-2025-9914 | Med | 0.28 | 4.3 | 0.00 | Oct 6, 2025 | The credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to gain unauthorized access. This could potentially affect the confidentiality of the application. | ||
| CVE-2025-58581 | Med | 0.28 | 4.3 | 0.00 | Oct 6, 2025 | When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker can thus obtain information about the technology used and the structure of the application. | ||
| CVE-2025-49192 | Med | 0.28 | 4.3 | 0.00 | Jun 12, 2025 | The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives. This could potentially reveal confidential information or allow others… | ||
| CVE-2025-49190 | Med | 0.28 | 4.3 | 0.00 | Jun 12, 2025 | The application is vulnerable to Server-Side Request Forgery (SSRF). An endpoint can be used to send server internal requests to other ports. | ||
| CVE-2023-5103 | Med | 0.28 | 4.3 | 0.00 | Oct 9, 2023 | Improper Restriction of Rendered UI Layers or Frames in RDT400 in SICK APU allows an unprivileged remote attacker to potentially reveal sensitive information via tricking a user into clicking on an actionable item using an iframe. | ||
| CVE-2025-49193 | Med | 0.27 | 4.2 | 0.00 | Jun 12, 2025 | The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code… | ||
| CVE-2026-22919 | Low | 0.25 | 3.8 | 0.00 | Jan 15, 2026 | An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site scripting (XSS) attacks, leading to the extraction of sensitive data. | ||
| CVE-2025-58578 | Low | 0.25 | 3.8 | 0.00 | Oct 6, 2025 | A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request. There are no quotas, checking mechanisms or restrictions to limit the creation. |
- risk 0.36cvss 5.6epss 0.00
The authentication process to the web server uses a challenge response procedure which inludes the nonce and additional information. This challenge can be used several times for login and is therefore vulnerable for a replay attack.
- risk 0.35cvss 5.3epss 0.01
Improper Restriction of Excessive Authentication Attempts in the SICK ICR890-4 could allow a remote attacker to brute-force user credentials.
- risk 0.35cvss 5.3epss 0.01
Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an remote attacker to influence the availability of the webserver by invocing a Slowloris style attack via HTTP requests.
- risk 0.35cvss 5.3epss 0.01
Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames by analyzing challenge responses from the server via the REST interface.
- risk 0.35cvss 5.3epss 0.01
Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis of source code.
- risk 0.34cvss 5.3epss 0.00
The application discloses all used components, versions and license information to unauthenticated actors, giving attackers the opportunity to target known security vulnerabilities of used components.
- risk 0.34cvss 5.3epss 0.01
Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer headers, which could allow an attacker to hijack the user's session and gain unauthorized access.
- risk 0.34cvss 5.3epss 0.00
Firmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover credentials and gain unauthorized access to the device.
- risk 0.34cvss 5.3epss 0.00
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.
- risk 0.34cvss 5.3epss 0.00
Multiple endpoints with sensitive information do not require authentication, making the application susceptible to information gathering.
- risk 0.34cvss 5.3epss 0.00
In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk that this sensitive data will be disclosed…
- risk 0.34cvss 5.3epss 0.00
The application provides access to a login protected H2 database for caching purposes. The username is prefilled.
- risk 0.34cvss 5.3epss 0.01
If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated and it’s possible to send giant payloads which are then logged.
- risk 0.34cvss 5.3epss 0.00
Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making the application vulnerable for user enumeration.
- risk 0.34cvss 5.3epss 0.00
The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure. There are modules activated that are not required for the operation of the FNADE4 web application. The functionality of the some modules pose a risk to the…
- risk 0.34cvss 5.3epss 0.00
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.
- risk 0.34cvss 5.3epss 0.00
The FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker to brute-force user passwords and potentially compromising the FTP server.
- risk 0.34cvss 5.3epss 0.00
The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag to false can lead to a higher possibility of Cross-Side-Scripting attacks which target the stored cookies.
- risk 0.34cvss 5.3epss 0.00
The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering.
- risk 0.34cvss 5.3epss 0.00
For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.
- risk 0.34cvss 5.3epss 0.00
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.
- risk 0.34cvss 5.3epss 0.01
The multiScan and picoScan are vulnerable to a denial-of-service (DoS) attack. A remote attacker can exploit this vulnerability by conducting a Slowloris-type attack, causing the web page to become unresponsive.
- risk 0.34cvss 5.3epss 0.01
Insufficient Control Flow Management in RDT400 in SICK APU allows an unprivileged remote attacker to potentially enable hidden functionality via HTTP requests.
- risk 0.34cvss 5.3epss 0.01
Files or Directories Accessible to External Parties in RDT400 in SICK APU allows an unprivileged remote attacker to download various files from the server via HTTP requests.
- risk 0.34cvss 5.3epss 0.00
Cleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device to disclose sensitive information by accessing a SD card.
- risk 0.34cvss 5.3epss 0.01
Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the FTP server from the response given during a failed login attempt.
- risk 0.34cvss 5.3epss 0.00
Cleartext Storage of Sensitive Information in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to potentially steal user credentials that are stored in the user’s browsers local storage via…
- risk 0.34cvss 5.3epss 0.01
Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users only. A malicious attacker could use this sensitive information’s to launch further attacks on the system.
- risk 0.34cvss 5.3epss 0.00
SICK Visionary-S CX up version 5.21.2.29154R are vulnerable to an Inadequate Encryption Strength vulnerability concerning the internal SSH interface solely used by SICK for recovering returned devices. The use of weak ciphers make it easier for an attacker to break the security…
- risk 0.32cvss 4.9epss 0.01
Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users only. A malicious attacker could use this sensitive information’s to launch further attacks on the system.
- risk 0.31cvss 4.8epss 0.00
Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it possible to attack other users that access the dashboard by including malicious code. The attack is only possible if the attacker…
- risk 0.29cvss 4.5epss 0.00
JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking.
- risk 0.29cvss 4.4epss 0.00
The VNC application stores its passwords encrypted within the registry but uses DES for encryption. As DES is broken, the original passwords can be recovered.
- risk 0.28cvss 4.3epss 0.00
Certain error messages returned by the application expose internal system details that should not be visible to end users, providing attackers with valuable reconnaissance information (like file paths, database errors, or software versions) that can be used to map the…
- risk 0.28cvss 4.3epss 0.00
An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted web pages, leading to the extraction of sensitive data.
- risk 0.28cvss 4.3epss 0.01
Improper input handling in a system endpoint may allow attackers to overload resources, causing a denial of service.
- risk 0.28cvss 4.3epss 0.00
An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without proper restrictions, potentially leading to service disruption or loss of configuration.
- risk 0.28cvss 4.3epss 0.00
An attacker with low privileges may be able to read files from specific directories on the device, potentially exposing sensitive information.
- risk 0.28cvss 4.3epss 0.00
An attacker with limited permissions may still be able to write files to specific locations on the device, potentially leading to system manipulation.
- risk 0.28cvss 4.3epss 0.00
Improper handling of a URL parameter may allow attackers to execute code in a user's browser after login. This can lead to the extraction of sensitive data.
- risk 0.28cvss 4.3epss 0.00
Improper validation of a login parameter may allow attackers to redirect users to malicious websites after authentication. This can lead to various risk including stealing credentials from unsuspecting users.
- risk 0.28cvss 4.3epss 0.00
An attacker may cause chunk-size mismatches that block file transfers and prevent subsequent transfers.
- risk 0.28cvss 4.3epss 0.00
The credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to gain unauthorized access. This could potentially affect the confidentiality of the application.
- risk 0.28cvss 4.3epss 0.00
When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker can thus obtain information about the technology used and the structure of the application.
- risk 0.28cvss 4.3epss 0.00
The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives. This could potentially reveal confidential information or allow others…
- risk 0.28cvss 4.3epss 0.00
The application is vulnerable to Server-Side Request Forgery (SSRF). An endpoint can be used to send server internal requests to other ports.
- risk 0.28cvss 4.3epss 0.00
Improper Restriction of Rendered UI Layers or Frames in RDT400 in SICK APU allows an unprivileged remote attacker to potentially reveal sensitive information via tricking a user into clicking on an actionable item using an iframe.
- risk 0.27cvss 4.2epss 0.00
The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code…
- risk 0.25cvss 3.8epss 0.00
An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site scripting (XSS) attacks, leading to the extraction of sensitive data.
- risk 0.25cvss 3.8epss 0.00
A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request. There are no quotas, checking mechanisms or restrictions to limit the creation.
Page 3 of 4