PT-2022-18498 · Sick · Msc800

Published

2022-04-11

·

Updated

2022-04-18

·

CVE-2022-27577

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions MSC800 versions prior to 4.15
Description The issue allows an attacker to predict the TCP initial sequence number, enabling them to send forged packets that appear to come from a trusted computer, potentially compromising services on the MSC800.
Recommendations For versions prior to 4.15, update to the newest firmware version released by SICK to resolve the issue.

Fix

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-27577

Affected Products

Msc800