PT-2022-28052 · Sick · Sick Sim2000St

Published

2022-12-16

·

Updated

2022-12-21

·

CVE-2022-47377

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SICK SIM2000ST Partnumber 2086502 versions prior to 1.13.4
Description A password recovery vulnerability allows an unprivileged remote attacker to gain access to the user level defined as RecoverableUserLevel by invoking the password recovery mechanism method. This leads to an increase in their privileges on the system, affecting the confidentiality, integrity, and availability of the system. An attacker can expect repeatable success by exploiting this issue.
Recommendations For SICK SIM2000ST Partnumber 2086502 versions prior to 1.13.4, update the firmware to a version >= 1.13.4 as soon as possible, available in the SICK Support Portal.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-47377

Affected Products

Sick Sim2000St