CVE Published: 15/05/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: SICK AG |
Vendor: SICK AG |
Product: SICK FTMG-ESD15AXX AIR FLOW SENSOR Status : PUBLISHED
CVE-2023-23446 Description
Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers
1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to download files by using a therefore unpriviledged account via the REST interface.
Metrics
CVSS Version: 3.1 |
Base Score: 7.5 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N