7.5

CVE-2023-23447

Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged
remote attacker to influence the availability of the webserver by invocing several open file requests via
the REST interface.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SickFtmg-esd20axx Firmware Version < 2.0
   SickFtmg-esd20axx Version-
SickFtmg-esd25axx Firmware Version < 2.0
   SickFtmg-esd25axx Version-
SickFtmg-esn40sxx Firmware Version < 2.0
   SickFtmg-esn40sxx Version-
SickFtmg-esn50sxx Firmware Version < 2.0
   SickFtmg-esn50sxx Version-
SickFtmg-esr50sxx Firmware Version < 2.0
   SickFtmg-esr50sxx Version-
SickFtmg-esr40sxx Firmware Version < 2.0
   SickFtmg-esr40sxx Version-
SickFtmg-esd15axx Firmware Version < 2.0
   SickFtmg-esd15axx Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.544
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
psirt@sick.de 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.