{"api_version":"1","generated_at":"2026-07-03T14:18:01+00:00","cve":"CVE-2023-23448","urls":{"html":"https://cve.report/CVE-2023-23448","api":"https://cve.report/api/cve/CVE-2023-23448.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-23448","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-23448"},"summary":{"title":"CVE-2023-23448","description":"Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a\nremote attacker to gain information about valid usernames via analysis of source code.","state":"PUBLISHED","assigner":"SICK AG","published_at":"2023-05-15 11:15:09","updated_at":"2026-06-01 13:16:23"},"problem_types":["CWE-540","CWE-668","CWE-540 CWE-540: Inclusion of Sensitive Information in Source Code"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"psirt@sick.de","type":"Secondary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://sick.com/psirt","name":"https://sick.com/psirt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"The SICK Product Security Incident Response Team (SICK PSIRT) | SICK","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf","name":"https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"404"},{"url":"https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.json","name":"https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.json","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-23448","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-23448","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"SICK AG","product":"SICK FTMG-ESD15AXX AIR FLOW SENSOR","version":"affected all firmware versions","platforms":[]},{"source":"CNA","vendor":"SICK AG","product":"SICK FTMG-ESD20AXX AIR FLOW SENSOR","version":"affected all firmware versions","platforms":[]},{"source":"CNA","vendor":"SICK AG","product":"SICK FTMG-ESD25AXX AIR FLOW SENSOR","version":"affected all firmware versions","platforms":[]},{"source":"CNA","vendor":"SICK AG","product":"SICK FTMG-ESN40SXX AIR FLOW SENSOR","version":"affected all firmware versions","platforms":[]},{"source":"CNA","vendor":"SICK AG","product":"SICK FTMG-ESN50SXX AIR FLOW SENSOR","version":"affected all firmware versions","platforms":[]},{"source":"CNA","vendor":"SICK AG","product":"SICK FTMG-ESR40SXX AIR FLOW SENSOR","version":"affected all firmware versions","platforms":[]},{"source":"CNA","vendor":"SICK AG","product":"SICK FTMG-ESR50SXX AIR FLOW SENSOR","version":"affected all firmware versions","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[{"source":"CNA","title":"","value":"Please make sure that you apply general security practices when operating the SICK FTMg\nlike network segmentation. The following General Security Practices and Operating Guidelines could\nmitigate the associated security risk.","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"23448","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"sick","cpe5":"ftmg-esd15axx","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23448","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"sick","cpe5":"ftmg-esd15axx_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23448","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"sick","cpe5":"ftmg-esd20axx","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23448","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"sick","cpe5":"ftmg-esd20axx_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23448","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"sick","cpe5":"ftmg-esd25axx","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23448","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"sick","cpe5":"ftmg-esd25axx_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23448","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"sick","cpe5":"ftmg-esn40sxx","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23448","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"sick","cpe5":"ftmg-esn40sxx_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23448","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"sick","cpe5":"ftmg-esn50sxx","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23448","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"sick","cpe5":"ftmg-esn50sxx_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23448","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"sick","cpe5":"ftmg-esr40sxx","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23448","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"sick","cpe5":"ftmg-esr40sxx_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23448","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"sick","cpe5":"ftmg-esr50sxx","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"23448","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"sick","cpe5":"ftmg-esr50sxx_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2023","cve_id":"23448","cve":"CVE-2023-23448","epss":"0.003770000","percentile":"0.595280000","score_date":"2026-06-04","updated_at":"2026-06-05 00:02:15"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-02T10:28:40.885Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["issue-tracking","x_transferred"],"url":"https://sick.com/psirt"},{"tags":["vendor-advisory","x_transferred"],"url":"https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf"},{"tags":["x_csaf","x_transferred"],"url":"https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.json"}],"title":"CVE Program Container"},{"metrics":[{"other":{"content":{"id":"CVE-2023-23448","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2025-01-23T19:14:42.455933Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2025-01-23T19:15:26.526Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"affected","product":"SICK FTMG-ESD15AXX AIR FLOW SENSOR","vendor":"SICK AG","versions":[{"status":"affected","version":"all firmware versions"}]},{"defaultStatus":"affected","product":"SICK FTMG-ESD20AXX AIR FLOW SENSOR","vendor":"SICK AG","versions":[{"status":"affected","version":"all firmware versions"}]},{"defaultStatus":"affected","product":"SICK FTMG-ESD25AXX AIR FLOW SENSOR","vendor":"SICK AG","versions":[{"status":"affected","version":"all firmware versions"}]},{"defaultStatus":"affected","product":"SICK FTMG-ESN40SXX AIR FLOW SENSOR","vendor":"SICK AG","versions":[{"status":"affected","version":"all firmware versions"}]},{"defaultStatus":"affected","product":"SICK FTMG-ESN50SXX AIR FLOW SENSOR","vendor":"SICK AG","versions":[{"status":"affected","version":"all firmware versions"}]},{"defaultStatus":"affected","product":"SICK FTMG-ESR40SXX AIR FLOW SENSOR","vendor":"SICK AG","versions":[{"status":"affected","version":"all firmware versions"}]},{"defaultStatus":"affected","product":"SICK FTMG-ESR50SXX AIR FLOW SENSOR","vendor":"SICK AG","versions":[{"status":"affected","version":"all firmware versions"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a\nremote attacker to gain information about valid usernames via analysis of source code."}],"value":"Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a\nremote attacker to gain information about valid usernames via analysis of source code."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-540","description":"CWE-540: Inclusion of Sensitive Information in Source Code","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-06-01T12:14:19.313Z","orgId":"a6863dd2-93fc-443d-bef1-79f0b5020988","shortName":"SICK AG"},"references":[{"tags":["issue-tracking"],"url":"https://sick.com/psirt"},{"tags":["vendor-advisory"],"url":"https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf"},{"tags":["x_csaf"],"url":"https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.json"}],"source":{"discovery":"INTERNAL"},"workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Please make sure that you apply general security practices when operating the SICK FTMg\nlike network segmentation. The following General Security Practices and Operating Guidelines could\nmitigate the associated security risk."}],"value":"Please make sure that you apply general security practices when operating the SICK FTMg\nlike network segmentation. The following General Security Practices and Operating Guidelines could\nmitigate the associated security risk."}],"x_generator":{"engine":"Vulnogram 0.1.0-dev"}}},"cveMetadata":{"assignerOrgId":"a6863dd2-93fc-443d-bef1-79f0b5020988","assignerShortName":"SICK AG","cveId":"CVE-2023-23448","datePublished":"2023-05-15T10:53:31.506Z","dateReserved":"2023-01-12T04:07:53.938Z","dateUpdated":"2026-06-01T12:14:19.313Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2023-05-15 11:15:09","lastModifiedDate":"2026-06-01 13:16:23","problem_types":["CWE-540","CWE-668","CWE-540 CWE-540: Inclusion of Sensitive Information in Source Code"],"metrics":{"cvssMetricV31":[{"source":"psirt@sick.de","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:sick:ftmg-esd20axx_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.0","matchCriteriaId":"E3882685-8678-47E4-995C-C3F6D9AD5668"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:sick:ftmg-esd20axx:-:*:*:*:*:*:*:*","matchCriteriaId":"16AD808F-900B-41EE-B90A-F9D67AAAD6BE"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:sick:ftmg-esd25axx_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.0","matchCriteriaId":"49D930E8-415C-4183-87A1-8D7F44247B67"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:sick:ftmg-esd25axx:-:*:*:*:*:*:*:*","matchCriteriaId":"24618A95-328C-47C9-B8EF-B4DF6E65D68E"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:sick:ftmg-esn40sxx_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.0","matchCriteriaId":"1DCC9C0B-7CCE-44E5-B25D-67BF971B4541"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:sick:ftmg-esn40sxx:-:*:*:*:*:*:*:*","matchCriteriaId":"290B016B-20B7-40C1-B825-6ED4774C4861"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:sick:ftmg-esn50sxx_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.0","matchCriteriaId":"E23D6018-1DFB-4516-82C9-3A3B09C2CBF9"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:sick:ftmg-esn50sxx:-:*:*:*:*:*:*:*","matchCriteriaId":"1B113D9E-8E61-4F9C-9E5B-2030EEFB133B"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:sick:ftmg-esr50sxx_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.0","matchCriteriaId":"77F2683F-B1B5-4033-97D4-ADF77B6B50E8"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:sick:ftmg-esr50sxx:-:*:*:*:*:*:*:*","matchCriteriaId":"A02547D3-5E40-41B3-A7B4-D63F60A5F80B"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:sick:ftmg-esr40sxx_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.0","matchCriteriaId":"9075A02A-C627-43DA-ACF7-776197B518C5"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:sick:ftmg-esr40sxx:-:*:*:*:*:*:*:*","matchCriteriaId":"7B887993-18A8-493F-97A1-A788FBD5A5B9"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:sick:ftmg-esd15axx_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"2.0","matchCriteriaId":"E9219CD8-34CE-45A2-904A-E7B1740706C2"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:sick:ftmg-esd15axx:-:*:*:*:*:*:*:*","matchCriteriaId":"FF162AA9-6645-4032-8D29-BAE2D60FBD9B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2023","CveId":"23448","Ordinal":"1","Title":"CVE-2023-23448","CVE":"CVE-2023-23448","Year":"2023"},"notes":[{"CveYear":"2023","CveId":"23448","Ordinal":"1","NoteData":"Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a\nremote attacker to gain information about valid usernames via analysis of source code.","Type":"Description","Title":"CVE-2023-23448"}]}}}