CVE-2023-23448
Summary
| CVE | CVE-2023-23448 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-15 11:15:00 UTC |
| Updated | 2023-05-25 13:50:00 UTC |
| Description | Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis of source code. |
Risk And Classification
Problem Types: CWE-668
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Sick | Ftmg-esd15axx | - | All | All | All |
| Operating System | Sick | Ftmg-esd15axx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esd20axx | - | All | All | All |
| Operating System | Sick | Ftmg-esd20axx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esd25axx | - | All | All | All |
| Operating System | Sick | Ftmg-esd25axx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esn40sxx | - | All | All | All |
| Operating System | Sick | Ftmg-esn40sxx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esn50sxx | - | All | All | All |
| Operating System | Sick | Ftmg-esn50sxx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esr40sxx | - | All | All | All |
| Operating System | Sick | Ftmg-esr40sxx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esr50sxx | - | All | All | All |
| Operating System | Sick | Ftmg-esr50sxx Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf | MISC | sick.com | |
| The SICK Product Security Incident Response Team (SICK PSIRT) | SICK | MISC | sick.com | |
| sick.com/.well-known/csaf/white/2023/sca-2023-0004.json | MISC | sick.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.