Описание
Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endpoints.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Product
- Vendor Advisory
- Vendor Advisory
- Product
Уязвимые конфигурации
Конфигурация 1Версия до 2.5.0 (исключая)
Одновременно
cpe:2.3:o:sick:icr890-4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sick:icr890-4:-:*:*:*:*:*:*:*
EPSS
Процентиль: 39%
0.00176
Низкий
8.2 High
CVSS3
7.5 High
CVSS3
Дефекты
CWE-284
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 8.2
github
больше 2 лет назад
Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endpoints.
EPSS
Процентиль: 39%
0.00176
Низкий
8.2 High
CVSS3
7.5 High
CVSS3
Дефекты
CWE-284
NVD-CWE-noinfo