CVE-2023-43697
- EPSS 0.35%
- Veröffentlicht 09.10.2023 13:15:10
- Zuletzt bearbeitet 21.11.2024 08:24:35
Modification of Assumed-Immutable Data (MAID) in RDT400 in SICK APU allows an unprivileged remote attacker to make the site unable to load necessary strings via changing file paths using HTTP requests.
CVE-2023-43698
- EPSS 0.11%
- Veröffentlicht 09.10.2023 13:15:10
- Zuletzt bearbeitet 21.11.2024 08:24:35
Improper Neutralization of Input During Web Page Generation (’Cross-site Scripting’) in RDT400 in SICK APU allows an unprivileged remote attacker to run arbitrary code in the clients browser via injecting code into the website.
CVE-2023-5100
- EPSS 0.08%
- Veröffentlicht 09.10.2023 13:15:10
- Zuletzt bearbeitet 21.11.2024 08:41:03
Cleartext Transmission of Sensitive Information in RDT400 in SICK APU allows an unprivileged remote attacker to retrieve potentially sensitive information via intercepting network traffic that is not encrypted.
CVE-2023-5101
- EPSS 0.14%
- Veröffentlicht 09.10.2023 13:15:10
- Zuletzt bearbeitet 21.11.2024 08:41:03
Files or Directories Accessible to External Parties in RDT400 in SICK APU allows an unprivileged remote attacker to download various files from the server via HTTP requests.
CVE-2023-5102
- EPSS 0.18%
- Veröffentlicht 09.10.2023 13:15:10
- Zuletzt bearbeitet 21.11.2024 08:41:03
Insufficient Control Flow Management in RDT400 in SICK APU allows an unprivileged remote attacker to potentially enable hidden functionality via HTTP requests.
CVE-2023-5103
- EPSS 0.14%
- Veröffentlicht 09.10.2023 13:15:10
- Zuletzt bearbeitet 21.11.2024 08:41:03
Improper Restriction of Rendered UI Layers or Frames in RDT400 in SICK APU allows an unprivileged remote attacker to potentially reveal sensitive information via tricking a user into clicking on an actionable item using an iframe.
CVE-2023-43696
- EPSS 0.22%
- Veröffentlicht 09.10.2023 12:15:10
- Zuletzt bearbeitet 21.11.2024 08:24:35
Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous access to the FTP server.
CVE-2023-43699
- EPSS 0.2%
- Veröffentlicht 09.10.2023 12:15:10
- Zuletzt bearbeitet 21.11.2024 08:24:35
Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU allows an unprivileged remote attacker to guess the password via trial-and-error as the login attempts are not limited.
CVE-2023-43700
- EPSS 0.19%
- Veröffentlicht 09.10.2023 12:15:10
- Zuletzt bearbeitet 21.11.2024 08:24:35
Missing Authorization in RDT400 in SICK APU allows an unprivileged remote attacker to modify data via HTTP requests that no not require authentication.