8.8
CVE-2023-5246
- EPSS 1.59%
- Veröffentlicht 23.10.2023 13:15:09
- Zuletzt bearbeitet 21.11.2024 08:41:22
- Quelle psirt@sick.de
- CVE-Watchlists
- Unerledigt
Authentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073, 1127717, 1130282, 1044074, 1121597, 1099832, 1051432, 1127487, 1069070, 1112296, 1044072, 1121596, 1099830 allows an unauthenticated remote attacker to potentially impact the availability, integrity and confidentiality of the gateways via an authentication bypass by capture-replay.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sick ≫ Fx0-gent00000 Firmware Version-
Sick ≫ Fx0-gent00010 Firmware Version-
Sick ≫ Fx0-gent00030 Firmware Version-
Sick ≫ Fx0-get00000 Firmware Version-
Sick ≫ Fx0-get00010 Firmware Version-
Sick ≫ Fx0-gmod00000 Firmware Version-
Sick ≫ Fx0-gmod00010 Firmware Version-
Sick ≫ Fx0-gmod00030 Firmware Version-
Sick ≫ Fx0-gpnt00000 Firmware Version-
Sick ≫ Fx0-gpnt00010 Firmware Version-
Sick ≫ Fx0-gpnt00030 Firmware Version-
Sick ≫ Fx0-gepr00000 Firmware Version-
Sick ≫ Fx0-gepr00010 Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.59% | 0.811 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| psirt@sick.de | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.