Sick

Icr890-4 Firmware

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 10.07.2023 16:15:55
  • Zuletzt bearbeitet 21.11.2024 08:16:52

Exposure of Sensitive Information to an Unauthorized Actor in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the system.

  • EPSS 0.18%
  • Veröffentlicht 10.07.2023 16:15:55
  • Zuletzt bearbeitet 21.11.2024 08:16:52

Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endpoints.

  • EPSS 0.09%
  • Veröffentlicht 10.07.2023 16:15:55
  • Zuletzt bearbeitet 21.11.2024 08:16:52

Cleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a remote attacker to gather sensitive information by intercepting network traffic that is not encrypted.

  • EPSS 0.56%
  • Veröffentlicht 10.07.2023 16:15:55
  • Zuletzt bearbeitet 21.11.2024 08:16:52

Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by changing settings of the device such as the IP address based on missing access control.

  • EPSS 0.14%
  • Veröffentlicht 10.07.2023 16:15:52
  • Zuletzt bearbeitet 21.11.2024 08:08:31

Unauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the device via HTTP requests.

  • EPSS 0.27%
  • Veröffentlicht 10.07.2023 16:15:52
  • Zuletzt bearbeitet 21.11.2024 08:08:31

Improper Restriction of Excessive Authentication Attempts in the SICK ICR890-4 could allow a remote attacker to brute-force user credentials.

  • EPSS 0.22%
  • Veröffentlicht 10.07.2023 16:15:52
  • Zuletzt bearbeitet 21.11.2024 08:08:31

Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the FTP server from the response given during a failed login attempt.

  • EPSS 0.04%
  • Veröffentlicht 10.07.2023 16:15:52
  • Zuletzt bearbeitet 21.11.2024 08:08:32

Cleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device to disclose sensitive information by accessing a SD card.