CVE-2023-23450
Summary
| CVE | CVE-2023-23450 |
|---|---|
| State | PUBLISHED |
| Assigner | SICK AG |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-15 11:15:09 UTC |
| Updated | 2026-06-01 13:16:23 UTC |
| Description | Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to use a password hash instead of an actual password to login to a valid user account via the REST interface. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.005320000 probability, percentile 0.676640000 (date 2026-06-04)
Problem Types: CWE-836 | CWE-287 | CWE-836 CWE-836 (Use of Password Hash Instead of Password for Authentication)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | [email protected] | Secondary | 6.2 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | CNA | CVSS | 6.2 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Sick | Ftmg-esd15axx | - | All | All | All |
| Operating System | Sick | Ftmg-esd15axx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esd20axx | - | All | All | All |
| Operating System | Sick | Ftmg-esd20axx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esd25axx | - | All | All | All |
| Operating System | Sick | Ftmg-esd25axx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esn40sxx | - | All | All | All |
| Operating System | Sick | Ftmg-esn40sxx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esn50sxx | - | All | All | All |
| Operating System | Sick | Ftmg-esn50sxx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esr40sxx | - | All | All | All |
| Operating System | Sick | Ftmg-esr40sxx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esr50sxx | - | All | All | All |
| Operating System | Sick | Ftmg-esr50sxx Firmware | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | SICK AG | SICK FTMG-ESD15AXX AIR FLOW SENSOR | affected all firmware versions | Not specified |
| CNA | SICK AG | SICK FTMG-ESD20AXX AIR FLOW SENSOR | affected all firmware versions | Not specified |
| CNA | SICK AG | SICK FTMG-ESD25AXX AIR FLOW SENSOR | affected all firmware versions | Not specified |
| CNA | SICK AG | SICK FTMG-ESN40SXX AIR FLOW SENSOR | affected all firmware versions | Not specified |
| CNA | SICK AG | SICK FTMG-ESN50SXX AIR FLOW SENSOR | affected all firmware versions | Not specified |
| CNA | SICK AG | SICK FTMG-ESR40SXX AIR FLOW SENSOR | affected all firmware versions | Not specified |
| CNA | SICK AG | SICK FTMG-ESR50SXX AIR FLOW SENSOR | affected all firmware versions | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| The SICK Product Security Incident Response Team (SICK PSIRT) | SICK | af854a3a-2127-422b-91ae-364da2661108 | sick.com | Vendor Advisory |
| sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf | af854a3a-2127-422b-91ae-364da2661108 | sick.com | Vendor Advisory |
| sick.com/.well-known/csaf/white/2023/sca-2023-0004.json | af854a3a-2127-422b-91ae-364da2661108 | sick.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Workarounds
CNA: Please make sure that you apply general security practices when operating the SICK FTMg like network segmentation. The following General Security Practices and Operating Guidelines could mitigate the associated security risk.
There are currently no legacy QID mappings associated with this CVE.