← Back

CVE-2023-23446

nvd nist
Published: May 15, 2023Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to download files by using a therefore unpriviledged account via the REST interface.

Affected (7)

7 products
Ftmg Esd20axx Firmware
Ftmg Esd25axx Firmware
Ftmg Esn40sxx Firmware
Ftmg Esn50sxx Firmware
Ftmg Esr50sxx Firmware
Ftmg Esr40sxx Firmware
Ftmg Esd15axx Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.0
Running on/withPlatform Versions
Sick
Ftmg Esd20axx
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.0
Running on/withPlatform Versions
Sick
Ftmg Esd25axx
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.0
Running on/withPlatform Versions
Sick
Ftmg Esn40sxx
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.0
Running on/withPlatform Versions
Sick
Ftmg Esn50sxx
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.0
Running on/withPlatform Versions
Sick
Ftmg Esr50sxx
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.0
Running on/withPlatform Versions
Sick
Ftmg Esr40sxx
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.0
Running on/withPlatform Versions
Sick
Ftmg Esd15axx
All versions

References (6)

Source: psirt@sick.de
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.