{"api_version":"1","generated_at":"2026-07-03T14:18:02+00:00","cve":"CVE-2023-23447","urls":{"html":"https://cve.report/CVE-2023-23447","api":"https://cve.report/api/cve/CVE-2023-23447.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-23447","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-23447"},"summary":{"title":"CVE-2023-23447","description":"Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged\nremote attacker to influence the availability of the webserver by invocing several open file requests via\nthe REST interface.","state":"PUBLISHED","assigner":"SICK AG","published_at":"2023-05-15 11:15:09","updated_at":"2026-06-01 13:16:23"},"problem_types":["CWE-400","CWE-400 CWE-400 Uncontrolled Resource Consumption"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"psirt@sick.de","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://sick.com/psirt","name":"https://sick.com/psirt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"The SICK Product Security Incident Response Team (SICK PSIRT) | SICK","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf","name":"https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"404"},{"url":"https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.json","name":"https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.json","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-23447","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-23447","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"SICK AG","product":"SICK FTMG-ESD15AXX AIR FLOW SENSOR","version":"affected v3.0.0.131.Release *","platforms":[]},{"source":"CNA","vendor":"SICK AG","product":"SICK FTMG-ESD20AXX AIR FLOW SENSOR","version":"affected v3.0.0.131.Release *","platforms":[]},{"source":"CNA","vendor":"SICK AG","product":"SICK FTMG-ESD25AXX AIR FLOW SENSOR","version":"affected v3.0.0.131.Release *","platforms":[]},{"source":"CNA","vendor":"SICK AG","product":"SICK FTMG-ESN40SXX AIR FLOW SENSOR","version":"affected v3.0.0.131.Release *","platforms":[]},{"source":"CNA","vendor":"SICK AG","product":"SICK FTMG-ESN50SXX AIR FLOW SENSOR","version":"affected v3.0.0.131.Release *","platforms":[]},{"source":"CNA","vendor":"SICK AG","product":"SICK FTMG-ESR40SXX AIR FLOW SENSOR","version":"affected v3.0.0.131.Release *","platforms":[]},{"source":"CNA","vendor":"SICK AG","product":"SICK FTMG-ESR50SXX AIR FLOW SENSOR","version":"affected v3.0.0.131.Release *","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"SICK has released a new major version v3.0.0.131.Release of the SICK FTMg firmware and\nrecommends updating to the newest version.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"23447","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"sick","cpe5":"ftmg-esd15axx","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23447","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"sick","cpe5":"ftmg-esd15axx_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23447","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"sick","cpe5":"ftmg-esd20axx","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23447","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"sick","cpe5":"ftmg-esd20axx_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23447","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"sick","cpe5":"ftmg-esd25axx","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23447","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"sick","cpe5":"ftmg-esd25axx_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23447","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"sick","cpe5":"ftmg-esn40sxx","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23447","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"sick","cpe5":"ftmg-esn40sxx_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23447","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"sick","cpe5":"ftmg-esn50sxx","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23447","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"sick","cpe5":"ftmg-esn50sxx_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23447","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"sick","cpe5":"ftmg-esr40sxx","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23447","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"sick","cpe5":"ftmg-esr40sxx_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23447","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"sick","cpe5":"ftmg-esr50sxx","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23447","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"sick","cpe5":"ftmg-esr50sxx_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2023","cve_id":"23447","cve":"CVE-2023-23447","epss":"0.007760000","percentile":"0.739920000","score_date":"2026-06-04","updated_at":"2026-06-05 00:02:15"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-02T10:28:40.882Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["issue-tracking","x_transferred"],"url":"https://sick.com/psirt"},{"tags":["vendor-advisory","x_transferred"],"url":"https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf"},{"tags":["x_csaf","x_transferred"],"url":"https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.json"}],"title":"CVE Program Container"},{"metrics":[{"other":{"content":{"id":"CVE-2023-23447","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2025-01-23T19:15:49.721428Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2025-01-23T19:15:53.962Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"affected","product":"SICK FTMG-ESD15AXX AIR FLOW SENSOR","vendor":"SICK AG","versions":[{"lessThan":"v3.0.0.131.Release","status":"affected","version":"0","versionType":"*"}]},{"defaultStatus":"affected","product":"SICK FTMG-ESD20AXX AIR FLOW SENSOR","vendor":"SICK AG","versions":[{"lessThan":"v3.0.0.131.Release","status":"affected","version":"0","versionType":"*"}]},{"defaultStatus":"affected","product":"SICK FTMG-ESD25AXX AIR FLOW SENSOR","vendor":"SICK AG","versions":[{"lessThan":"v3.0.0.131.Release","status":"affected","version":"0","versionType":"*"}]},{"defaultStatus":"affected","product":"SICK FTMG-ESN40SXX AIR FLOW SENSOR","vendor":"SICK AG","versions":[{"lessThan":"v3.0.0.131.Release","status":"affected","version":"0","versionType":"*"}]},{"defaultStatus":"affected","product":"SICK FTMG-ESN50SXX AIR FLOW SENSOR","vendor":"SICK AG","versions":[{"lessThan":"v3.0.0.131.Release","status":"affected","version":"0","versionType":"*"}]},{"defaultStatus":"affected","product":"SICK FTMG-ESR40SXX AIR FLOW SENSOR","vendor":"SICK AG","versions":[{"lessThan":"v3.0.0.131.Release","status":"affected","version":"0","versionType":"*"}]},{"defaultStatus":"affected","product":"SICK FTMG-ESR50SXX AIR FLOW SENSOR","vendor":"SICK AG","versions":[{"lessThan":"v3.0.0.131.Release","status":"affected","version":"0","versionType":"*"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged\nremote attacker to influence the availability of the webserver by invocing several open file requests via\nthe REST interface."}],"value":"Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged\nremote attacker to influence the availability of the webserver by invocing several open file requests via\nthe REST interface."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-400","description":"CWE-400 Uncontrolled Resource Consumption","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-06-01T12:18:09.574Z","orgId":"a6863dd2-93fc-443d-bef1-79f0b5020988","shortName":"SICK AG"},"references":[{"tags":["issue-tracking"],"url":"https://sick.com/psirt"},{"tags":["vendor-advisory"],"url":"https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf"},{"tags":["x_csaf"],"url":"https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.json"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"SICK has released a new major version v3.0.0.131.Release of the SICK FTMg firmware and\nrecommends updating to the newest version."}],"value":"SICK has released a new major version v3.0.0.131.Release of the SICK FTMg firmware and\nrecommends updating to the newest version."}],"source":{"discovery":"INTERNAL"},"x_generator":{"engine":"Vulnogram 0.1.0-dev"}}},"cveMetadata":{"assignerOrgId":"a6863dd2-93fc-443d-bef1-79f0b5020988","assignerShortName":"SICK AG","cveId":"CVE-2023-23447","datePublished":"2023-05-15T10:53:05.800Z","dateReserved":"2023-01-12T04:07:53.938Z","dateUpdated":"2026-06-01T12:18:09.574Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2023-05-15 11:15:09","lastModifiedDate":"2026-06-01 13:16:23","problem_types":["CWE-400","CWE-400 CWE-400 Uncontrolled Resource Consumption"],"metrics":{"cvssMetricV31":[{"source":"psirt@sick.de","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:sick:ftmg-esd20axx_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.0","matchCriteriaId":"E3882685-8678-47E4-995C-C3F6D9AD5668"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:sick:ftmg-esd20axx:-:*:*:*:*:*:*:*","matchCriteriaId":"16AD808F-900B-41EE-B90A-F9D67AAAD6BE"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:sick:ftmg-esd25axx_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.0","matchCriteriaId":"49D930E8-415C-4183-87A1-8D7F44247B67"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:sick:ftmg-esd25axx:-:*:*:*:*:*:*:*","matchCriteriaId":"24618A95-328C-47C9-B8EF-B4DF6E65D68E"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:sick:ftmg-esn40sxx_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.0","matchCriteriaId":"1DCC9C0B-7CCE-44E5-B25D-67BF971B4541"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:sick:ftmg-esn40sxx:-:*:*:*:*:*:*:*","matchCriteriaId":"290B016B-20B7-40C1-B825-6ED4774C4861"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:sick:ftmg-esn50sxx_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.0","matchCriteriaId":"E23D6018-1DFB-4516-82C9-3A3B09C2CBF9"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:sick:ftmg-esn50sxx:-:*:*:*:*:*:*:*","matchCriteriaId":"1B113D9E-8E61-4F9C-9E5B-2030EEFB133B"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:sick:ftmg-esr50sxx_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.0","matchCriteriaId":"77F2683F-B1B5-4033-97D4-ADF77B6B50E8"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:sick:ftmg-esr50sxx:-:*:*:*:*:*:*:*","matchCriteriaId":"A02547D3-5E40-41B3-A7B4-D63F60A5F80B"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:sick:ftmg-esr40sxx_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.0","matchCriteriaId":"9075A02A-C627-43DA-ACF7-776197B518C5"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:sick:ftmg-esr40sxx:-:*:*:*:*:*:*:*","matchCriteriaId":"7B887993-18A8-493F-97A1-A788FBD5A5B9"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:sick:ftmg-esd15axx_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.0","matchCriteriaId":"E9219CD8-34CE-45A2-904A-E7B1740706C2"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:sick:ftmg-esd15axx:-:*:*:*:*:*:*:*","matchCriteriaId":"FF162AA9-6645-4032-8D29-BAE2D60FBD9B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2023","CveId":"23447","Ordinal":"1","Title":"CVE-2023-23447","CVE":"CVE-2023-23447","Year":"2023"},"notes":[{"CveYear":"2023","CveId":"23447","Ordinal":"1","NoteData":"Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged\nremote attacker to influence the availability of the webserver by invocing several open file requests via\nthe REST interface.","Type":"Description","Title":"CVE-2023-23447"}]}}}