6.5
CVE-2023-5100
- EPSS 0.08%
- Veröffentlicht 09.10.2023 13:15:10
- Zuletzt bearbeitet 21.11.2024 08:41:03
- Quelle psirt@sick.de
- CVE-Watchlists
- Unerledigt
Cleartext Transmission of Sensitive Information in RDT400 in SICK APU allows an unprivileged remote attacker to retrieve potentially sensitive information via intercepting network traffic that is not encrypted.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sick ≫ Apu0200 Firmware Version < 4.0.0.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.229 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
| psirt@sick.de | 5.9 | 1.6 | 4.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
|
CWE-319 Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.