CVE-2023-31408
Summary
| CVE | CVE-2023-31408 |
|---|---|
| State | PUBLISHED |
| Assigner | SICK AG |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-15 11:15:09 UTC |
| Updated | 2026-06-01 09:16:14 UTC |
| Description | Cleartext Storage of Sensitive Information in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to potentially steal user credentials that are stored in the user’s browsers local storage via cross-site-scripting attacks. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.002180000 probability, percentile 0.443570000 (date 2026-06-03)
Problem Types: CWE-312 | CWE-312 CWE-312 (Cleartext Storage of Sensitive Information)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | [email protected] | Secondary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
| 3.1 | CNA | CVSS | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Sick | Ftmg-esd15axx | - | All | All | All |
| Operating System | Sick | Ftmg-esd15axx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esd20axx | - | All | All | All |
| Operating System | Sick | Ftmg-esd20axx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esd25axx | - | All | All | All |
| Operating System | Sick | Ftmg-esd25axx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esn40sxx | - | All | All | All |
| Operating System | Sick | Ftmg-esn40sxx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esn50sxx | - | All | All | All |
| Operating System | Sick | Ftmg-esn50sxx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esr40sxx | - | All | All | All |
| Operating System | Sick | Ftmg-esr40sxx Firmware | All | All | All | All |
| Hardware | Sick | Ftmg-esr50sxx | - | All | All | All |
| Operating System | Sick | Ftmg-esr50sxx Firmware | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | SICK AG | SICK FTMG-ESD15AXX AIR FLOW SENSOR | affected all firmware versions | Not specified |
| CNA | SICK AG | SICK FTMG-ESD20AXX AIR FLOW SENSOR | affected all firmware versions | Not specified |
| CNA | SICK AG | SICK FTMG-ESD25AXX AIR FLOW SENSOR | affected all firmware versions | Not specified |
| CNA | SICK AG | SICK FTMG-ESN40SXX AIR FLOW SENSOR | affected all firmware versions | Not specified |
| CNA | SICK AG | SICK FTMG-ESN50SXX AIR FLOW SENSOR | affected all firmware versions | Not specified |
| CNA | SICK AG | SICK FTMG-ESR40SXX AIR FLOW SENSOR | affected all firmware versions | Not specified |
| CNA | SICK AG | SICK FTMG-ESR50SXX AIR FLOW SENSOR | affected all firmware versions | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| The SICK Product Security Incident Response Team (SICK PSIRT) | SICK | af854a3a-2127-422b-91ae-364da2661108 | sick.com | Vendor Advisory |
| sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf | af854a3a-2127-422b-91ae-364da2661108 | sick.com | Vendor Advisory |
| sick.com/.well-known/csaf/white/2023/sca-2023-0004.json | af854a3a-2127-422b-91ae-364da2661108 | sick.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Workarounds
CNA: Please make sure that you apply general security practices when operating the SICK FTMg like network segmentation. The following General Security Practices and Operating Guidelines could mitigate the associated security risk.
There are currently no legacy QID mappings associated with this CVE.