CVE-2020-2075
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Platform mechanism AutoIP allows remote attackers to reboot the device via a crafted packet in SICK AG solutions Bulkscan LMS111, Bulkscan LMS511, CLV62x – CLV65x, ICR890-3, LMS10x, LMS11x, LMS15x, LMS12x, LMS13x, LMS14x, LMS5xx, LMS53x, MSC800, RFH.
Affected (32)
Products: Sick: Lms111 Firmware, Lms511 Firmware, Clv620 Firmware, Clv622 Firmware, Clv621 Firmware, Icr890 3 Firmware, Msc800 Firmware, Rfh Firmware, Clv650 Firmware, Clv651 Firmware, Clv631 Firmware, Clv630 Firmware, Clv632 Firmware, Clv640 Firmware, Clv642 Firmware, Lms100 Firmware, Lms101 Firmware, Lms153 Firmware, Lms151 Firmware, Lms133 Firmware, Lms142 Firmware, Lms143 Firmware, Lms131 Firmware, Lms121 Firmware, Lms123 Firmware, Lms122 Firmware, Lms141 Firmware, Lms531 Firmware, Lms500 Firmware, Icr890 3.5 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.04 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.30 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sick Clv620 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sick Clv622 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sick Clv621 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sick Icr890 3 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.10 |
| Running on/with | Platform Versions |
|---|---|
Sick Msc800 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sick Rfh | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sick Clv650 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sick Clv651 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sick Clv631 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sick Clv630 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sick Clv632 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sick Clv640 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sick Clv642 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0 |
| Running on/with | Platform Versions |
|---|---|
Sick Lms100 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0 |
| Running on/with | Platform Versions |
|---|---|
Sick Lms101 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0 |
| Running on/with | Platform Versions |
|---|---|
Sick Lms111 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0 |
| Running on/with | Platform Versions |
|---|---|
Sick Lms153 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0 |
| Running on/with | Platform Versions |
|---|---|
Sick Lms151 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.10 |
| Running on/with | Platform Versions |
|---|---|
Sick Lms133 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.10 |
| Running on/with | Platform Versions |
|---|---|
Sick Lms142 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.10 |
| Running on/with | Platform Versions |
|---|---|
Sick Lms143 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.10 |
| Running on/with | Platform Versions |
|---|---|
Sick Lms131 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.10 |
| Running on/with | Platform Versions |
|---|---|
Sick Lms121 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.10 |
| Running on/with | Platform Versions |
|---|---|
Sick Lms123 | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.10 |
| Running on/with | Platform Versions |
|---|---|
Sick Lms122 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.10 |
| Running on/with | Platform Versions |
|---|---|
Sick Lms141 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sick Lms511 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sick Lms531 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sick Lms500 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Sick Icr890 3.5 | All versions |
Related CWEs
CWE-703
Improper Check or Handling of Exceptional Conditions
The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.
CWE-755
Improper Handling of Exceptional Conditions
The product does not handle or incorrectly handles an exceptional condition.
References (2)
Source: psirt@sick.de
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.