CVE-2023-23445
Summary
| CVE | CVE-2023-23445 |
|---|---|
| State | PUBLISHED |
| Assigner | SICK AG |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-15 11:15:09 UTC |
| Updated | 2026-06-01 13:16:22 UTC |
| Description | Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to gain unauthorized access to data fields by using a therefore unpriviledged account via the REST interface. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.004090000 probability, percentile 0.615930000 (date 2026-06-04)
Problem Types: CWE-284 | CWE-863 | CWE-284 CWE-284 Improper Access Control
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | [email protected] | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | CNA | CVSS | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Sick | Ftmg-esd15axx | - | All | All | All |
| Operating System | Sick | Ftmg-esd15axx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esd20axx | - | All | All | All |
| Operating System | Sick | Ftmg-esd20axx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esd25axx | - | All | All | All |
| Operating System | Sick | Ftmg-esd25axx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esn40sxx | - | All | All | All |
| Operating System | Sick | Ftmg-esn40sxx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esn50sxx | - | All | All | All |
| Operating System | Sick | Ftmg-esn50sxx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esr40sxx | - | All | All | All |
| Operating System | Sick | Ftmg-esr40sxx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esr50sxx | - | All | All | All |
| Operating System | Sick | Ftmg-esr50sxx Firmware | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | SICK AG | SICK FTMG-ESD15AXX AIR FLOW SENSOR | affected all firmware versions | Not specified |
| CNA | SICK AG | SICK FTMG-ESD20AXX AIR FLOW SENSOR | affected all firmware versions | Not specified |
| CNA | SICK AG | SICK FTMG-ESD25AXX AIR FLOW SENSOR | affected all firmware versions | Not specified |
| CNA | SICK AG | SICK FTMG-ESN40SXX AIR FLOW SENSOR | affected all firmware versions | Not specified |
| CNA | SICK AG | SICK FTMG-ESN50SXX AIR FLOW SENSOR | affected all firmware versions | Not specified |
| CNA | SICK AG | SICK FTMG-ESR40SXX AIR FLOW SENSOR | affected all firmware versions | Not specified |
| CNA | SICK AG | SICK FTMG-ESR50SXX AIR FLOW SENSOR | affected all firmware versions | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| The SICK Product Security Incident Response Team (SICK PSIRT) | SICK | af854a3a-2127-422b-91ae-364da2661108 | sick.com | Vendor Advisory |
| sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf | af854a3a-2127-422b-91ae-364da2661108 | sick.com | Vendor Advisory |
| sick.com/.well-known/csaf/white/2023/sca-2023-0004.json | af854a3a-2127-422b-91ae-364da2661108 | sick.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Workarounds
CNA: Please make sure that you apply general security practices when operating the SICK FTMg like network segmentation. The following General Security Practices and Operating Guidelines could mitigate the associated security risk.
There are currently no legacy QID mappings associated with this CVE.