PT-2022-18498 · Sick · Msc800
Published
2022-04-11
·
Updated
2022-04-18
·
CVE-2022-27577
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
MSC800 versions prior to 4.15
Description
The issue allows an attacker to predict the TCP initial sequence number, enabling them to send forged packets that appear to come from a trusted computer, potentially compromising services on the MSC800.
Recommendations
For versions prior to 4.15, update to the newest firmware version released by SICK to resolve the issue.
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Msc800