CVE-2023-5246
Summary
| CVE | CVE-2023-5246 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-23 13:15:00 UTC |
| Updated | 2023-10-31 11:58:00 UTC |
| Description | Authentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073, 1127717, 1130282, 1044074, 1121597, 1099832, 1051432, 1127487, 1069070, 1112296, 1044072, 1121596, 1099830 allows an unauthenticated remote attacker to potentially impact the availability, integrity and confidentiality of the gateways via an authentication bypass by capture-replay. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Sick | Fx0-gent00000 | - | All | All | All |
| Operating System | Sick | Fx0-gent00000 Firmware | - | All | All | All |
| Hardware | Sick | Fx0-gent00010 | - | All | All | All |
| Operating System | Sick | Fx0-gent00010 Firmware | - | All | All | All |
| Hardware | Sick | Fx0-gent00030 | - | All | All | All |
| Operating System | Sick | Fx0-gent00030 Firmware | - | All | All | All |
| Hardware | Sick | Fx0-gepr00000 | - | All | All | All |
| Operating System | Sick | Fx0-gepr00000 Firmware | - | All | All | All |
| Hardware | Sick | Fx0-gepr00010 | - | All | All | All |
| Operating System | Sick | Fx0-gepr00010 Firmware | - | All | All | All |
| Hardware | Sick | Fx0-get00000 | - | All | All | All |
| Operating System | Sick | Fx0-get00000 Firmware | - | All | All | All |
| Hardware | Sick | Fx0-get00010 | - | All | All | All |
| Operating System | Sick | Fx0-get00010 Firmware | - | All | All | All |
| Hardware | Sick | Fx0-gmod00000 | - | All | All | All |
| Operating System | Sick | Fx0-gmod00000 Firmware | - | All | All | All |
| Hardware | Sick | Fx0-gmod00010 | - | All | All | All |
| Operating System | Sick | Fx0-gmod00010 Firmware | - | All | All | All |
| Hardware | Sick | Fx0-gmod00030 | - | All | All | All |
| Operating System | Sick | Fx0-gmod00030 Firmware | - | All | All | All |
| Hardware | Sick | Fx0-gpnt00000 | - | All | All | All |
| Operating System | Sick | Fx0-gpnt00000 Firmware | - | All | All | All |
| Hardware | Sick | Fx0-gpnt00010 | - | All | All | All |
| Operating System | Sick | Fx0-gpnt00010 Firmware | - | All | All | All |
| Hardware | Sick | Fx0-gpnt00030 | - | All | All | All |
| Operating System | Sick | Fx0-gpnt00030 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| sick.com/.well-known/csaf/white/2023/sca-2023-0011.json | MISC | sick.com | |
| sick.com/.well-known/csaf/white/2023/sca-2023-0011.pdf | MISC | sick.com | |
| The SICK Product Security Incident Response Team (SICK PSIRT) | SICK | MISC | sick.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.