CVE-2023-23444
Summary
| CVE | CVE-2023-23444 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-12 13:15:00 UTC |
| Updated | 2023-05-26 18:15:00 UTC |
| Description | Missing Authentication for Critical Function in SICK Flexi Classic and Flexi Soft Gateways with Partnumbers 1042193, 1042964, 1044078, 1044072, 1044073, 1044074, 1099830, 1099832, 1127717, 1069070, 1112296, 1051432, 1102420, 1127487, 1121596, 1121597 allows an unauthenticated remote attacker to influence the availability of the device by changing the IP settings of the device via broadcasted UDP packets. |
Risk And Classification
Problem Types: CWE-306
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Sick | Fx0-gent00000 | - | All | All | All |
| Operating System | Sick | Fx0-gent00000 Firmware | - | All | All | All |
| Hardware | Sick | Fx0-gent00010 | - | All | All | All |
| Operating System | Sick | Fx0-gent00010 Firmware | - | All | All | All |
| Hardware | Sick | Fx0-gent00030 | - | All | All | All |
| Operating System | Sick | Fx0-gent00030 Firmware | - | All | All | All |
| Hardware | Sick | Fx0-gmod00000 | - | All | All | All |
| Operating System | Sick | Fx0-gmod00000 Firmware | - | All | All | All |
| Hardware | Sick | Fx0-gmod00010 | - | All | All | All |
| Operating System | Sick | Fx0-gmod00010 Firmware | - | All | All | All |
| Hardware | Sick | Fx0-gpnt00000 | - | All | All | All |
| Operating System | Sick | Fx0-gpnt00000 Firmware | - | All | All | All |
| Hardware | Sick | Fx0-gpnt00010 | - | All | All | All |
| Operating System | Sick | Fx0-gpnt00010 Firmware | - | All | All | All |
| Hardware | Sick | Fx0-gpnt00030 | - | All | All | All |
| Operating System | Sick | Fx0-gpnt00030 Firmware | - | All | All | All |
| Hardware | Sick | Ue410-en1 | - | All | All | All |
| Operating System | Sick | Ue410-en1 Firmware | - | All | All | All |
| Hardware | Sick | Ue410-en3 | - | All | All | All |
| Operating System | Sick | Ue410-en3 Firmware | - | All | All | All |
| Hardware | Sick | Ue410-en4 | - | All | All | All |
| Operating System | Sick | Ue410-en4 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| sick.com/.well-known/csaf/white/2023/sca-2023-0003.pdf | MISC | sick.com | |
| The SICK Product Security Incident Response Team (SICK PSIRT) | SICK | MISC | sick.com | |
| sick.com/.well-known/csaf/white/2023/sca-2023-0003.json | MISC | sick.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.