sick CVE Vulnerabilities & Metrics

Focus on sick vulnerabilities and metrics.

Last updated: 15 Feb 2026, 23:25 UTC

About sick Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with sick. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total sick CVEs: 90
Earliest CVE date: 01 Jul 2019, 21:15 UTC
Latest CVE date: 15 Jan 2026, 14:16 UTC

Latest CVE reference: CVE-2026-22644

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 45

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): -100.0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): -100.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical sick CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 0.58

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 81
4.0-6.9 7
7.0-8.9 2
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS sick CVEs

These are the five CVEs with the highest CVSS scores for sick, sorted by severity first and recency.

All CVEs for sick

CVE-2026-22644 sick vulnerability CVSS: 0 15 Jan 2026, 14:16 UTC

Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer headers, which could allow an attacker to hijack the user's session and gain unauthorized access.

CVE-2026-22920 sick vulnerability CVSS: 0 15 Jan 2026, 13:16 UTC

The device's passwords have not been adequately salted, making them vulnerable to password extraction attacks.

CVE-2026-22918 sick vulnerability CVSS: 0 15 Jan 2026, 13:16 UTC

An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted web pages, leading to the extraction of sensitive data.

CVE-2026-22916 sick vulnerability CVSS: 0 15 Jan 2026, 13:16 UTC

An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without proper restrictions, potentially leading to service disruption or loss of configuration.

CVE-2026-22915 sick vulnerability CVSS: 0 15 Jan 2026, 13:16 UTC

An attacker with low privileges may be able to read files from specific directories on the device, potentially exposing sensitive information.

CVE-2026-22914 sick vulnerability CVSS: 0 15 Jan 2026, 13:16 UTC

An attacker with limited permissions may still be able to write files to specific locations on the device, potentially leading to system manipulation.

CVE-2026-22911 sick vulnerability CVSS: 0 15 Jan 2026, 13:16 UTC

Firmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover credentials and gain unauthorized access to the device.

CVE-2026-22910 sick vulnerability CVSS: 0 15 Jan 2026, 13:16 UTC

The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the integrity of the system.

CVE-2026-22909 sick vulnerability CVSS: 0 15 Jan 2026, 13:16 UTC

Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potentially disrupting system operations.

CVE-2025-59463 sick vulnerability CVSS: 0 27 Oct 2025, 11:15 UTC

An attacker may cause chunk-size mismatches that block file transfers and prevent subsequent transfers.

CVE-2025-59462 sick vulnerability CVSS: 0 27 Oct 2025, 11:15 UTC

An attacker who tampers with the C++ CLI client may crash the UpdateService during file transfers, disrupting updates and availability.

CVE-2025-59461 sick vulnerability CVSS: 0 27 Oct 2025, 11:15 UTC

A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services.

CVE-2025-10561 sick vulnerability CVSS: 0 27 Oct 2025, 10:15 UTC

The device is running an outdated operating system, which may be susceptible to known vulnerabilities.

CVE-2025-9914 sick vulnerability CVSS: 0 06 Oct 2025, 07:15 UTC

The credentials of the users stored in the system's local database can be used for the log in, making it possible for an attacker to gain unauthorized access. This could potentially affect the confidentiality of the application.

CVE-2025-9913 sick vulnerability CVSS: 0 06 Oct 2025, 07:15 UTC

JavaScript can be ran inside the address bar via the dashboard "Open in new Tab" Button, making the application vulnerable to session hijacking.

CVE-2025-58591 sick vulnerability CVSS: 0 06 Oct 2025, 07:15 UTC

A remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, making the application vulnerable for gathering sensitive information.

CVE-2025-58590 sick vulnerability CVSS: 0 06 Oct 2025, 07:15 UTC

It's possible to brute force folders and files, what can be used by an attacker to steal sensitve information.

CVE-2025-58589 sick vulnerability CVSS: 0 06 Oct 2025, 07:15 UTC

When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker thus receives information about the technology used and the structure of the application.

CVE-2025-58587 sick vulnerability CVSS: 0 06 Oct 2025, 07:15 UTC

The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possible for an attacker to guess user credentials.

CVE-2025-58586 sick vulnerability CVSS: 0 06 Oct 2025, 07:15 UTC

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.

CVE-2025-58585 sick vulnerability CVSS: 0 06 Oct 2025, 07:15 UTC

Multiple endpoints with sensitive information do not require authentication, making the application susceptible to information gathering.

CVE-2025-58584 sick vulnerability CVSS: 0 06 Oct 2025, 07:15 UTC

In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk that this sensitive data will be disclosed unintentionally.

CVE-2025-58583 sick vulnerability CVSS: 0 06 Oct 2025, 07:15 UTC

The application provides access to a login protected H2 database for caching purposes. The username is prefilled.

CVE-2025-58582 sick vulnerability CVSS: 0 06 Oct 2025, 07:15 UTC

If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated and it’s possible to send giant payloads which are then logged.

CVE-2025-58581 sick vulnerability CVSS: 0 06 Oct 2025, 07:15 UTC

When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker can thus obtain information about the technology used and the structure of the application.

CVE-2025-58580 sick vulnerability CVSS: 0 06 Oct 2025, 07:15 UTC

An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation of the input data, an attacker can create manipulated log entries and thus falsify or dilute logs, for example.

CVE-2025-58579 sick vulnerability CVSS: 0 06 Oct 2025, 07:15 UTC

Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making the application vulnerable for user enumeration.

CVE-2025-58578 sick vulnerability CVSS: 0 06 Oct 2025, 07:15 UTC

A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request. There are no quotas, checking mechanisms or restrictions to limit the creation.

CVE-2025-49200 sick vulnerability CVSS: 0 12 Jun 2025, 15:15 UTC

The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downloading and decompressing the backup files.

CVE-2025-49199 sick vulnerability CVSS: 0 12 Jun 2025, 15:15 UTC

The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it. This allows the attacker to disrupt the application by configuring the services in a way that they are unable to run, making the application unusable. They can redirect traffic that is meant to be internal to their own hosted services and gathering information.

CVE-2025-49198 sick vulnerability CVSS: 0 12 Jun 2025, 15:15 UTC

The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of an active user by computing plausible tokens.

CVE-2025-49196 sick vulnerability CVSS: 0 12 Jun 2025, 15:15 UTC

A service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive information, modify data in unexpected ways or spoof identities of other users or devices, affecting the confidentiality and integrity of the device.

CVE-2025-49195 sick vulnerability CVSS: 0 12 Jun 2025, 15:15 UTC

The FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker to brute-force user passwords and potentially compromising the FTP server.

CVE-2025-49194 sick vulnerability CVSS: 0 12 Jun 2025, 15:15 UTC

The server supports authentication methods in which credentials are sent in plaintext over unencrypted channels. If an attacker were to intercept traffic between a client and this server, the credentials would be exposed.

CVE-2025-49193 sick vulnerability CVSS: 0 12 Jun 2025, 15:15 UTC

The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code (XSS attacks).

CVE-2025-49192 sick vulnerability CVSS: 0 12 Jun 2025, 15:15 UTC

The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives. This could potentially reveal confidential information or allow others to take control of their computer while clicking on seemingly innocuous objects.

CVE-2025-49191 sick vulnerability CVSS: 0 12 Jun 2025, 14:15 UTC

Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it possible to attack other users that access the dashboard by including malicious code. The attack is only possible if the attacker is authorized to create new dashboards or iFrame widgets.

CVE-2025-49190 sick vulnerability CVSS: 0 12 Jun 2025, 14:15 UTC

The application is vulnerable to Server-Side Request Forgery (SSRF). An endpoint can be used to send server internal requests to other ports.

CVE-2025-49188 sick vulnerability CVSS: 0 12 Jun 2025, 14:15 UTC

The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering.

CVE-2025-49187 sick vulnerability CVSS: 0 12 Jun 2025, 14:15 UTC

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.

CVE-2025-49186 sick vulnerability CVSS: 0 12 Jun 2025, 14:15 UTC

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

CVE-2025-49185 sick vulnerability CVSS: 0 12 Jun 2025, 14:15 UTC

The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboard widgets can inject malicious JavaScript code into the Transform Function which will be executed when the widget receives data from its data source.

CVE-2025-49184 sick vulnerability CVSS: 0 12 Jun 2025, 14:15 UTC

A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration settings of the product.

CVE-2025-49183 sick vulnerability CVSS: 0 12 Jun 2025, 14:15 UTC

All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor and the webserver. This leads to the possibility of information gathering and downloading media files.

CVE-2025-49181 sick vulnerability CVSS: 0 12 Jun 2025, 14:15 UTC

Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive information. An attacker could also send HTTP POST requests to modify the log files’ root path as well as the TCP ports the service is running on, leading to a Denial of Service attack.

CVE-2023-5246 sick vulnerability CVSS: 0 23 Oct 2023, 13:15 UTC

Authentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073, 1127717, 1130282, 1044074, 1121597, 1099832, 1051432, 1127487, 1069070, 1112296, 1044072, 1121596, 1099830 allows an unauthenticated remote attacker to potentially impact the availability, integrity and confidentiality of the gateways via an authentication bypass by capture-replay.

CVE-2023-5288 sick vulnerability CVSS: 0 29 Sep 2023, 12:15 UTC

A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings. The adversary may also reset the SIM and in the worst case upload a new firmware version to the device.

CVE-2023-4420 sick vulnerability CVSS: 0 24 Aug 2023, 19:15 UTC

A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK LMS5xx. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive information. The attacker can exploit this weakness to eavesdrop on the communication between the LMS5xx and the Client, and potentially manipulate the data being transmitted.

CVE-2023-4419 sick vulnerability CVSS: 0 24 Aug 2023, 19:15 UTC

The LMS5xx uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure settings and /or disrupt the functionality of the device.

CVE-2023-4418 sick vulnerability CVSS: 0 24 Aug 2023, 19:15 UTC

A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack. By exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests, overwhelming its resources and causing it to become unresponsive or unavailable for legitimate users.

CVE-2023-31412 sick vulnerability CVSS: 0 24 Aug 2023, 19:15 UTC

The LMS5xx uses weak hash generation methods, resulting in the creation of insecure hashs. If an attacker manages to retrieve the hash, it could lead to collision attacks and the potential retrieval of the password.

CVE-2023-31411 sick vulnerability CVSS: 0 19 Jun 2023, 15:15 UTC

A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication. The lack of authentication in the API allows the attacker to potentially compromise the functionality of the EventCam App.

CVE-2023-31410 sick vulnerability CVSS: 0 19 Jun 2023, 15:15 UTC

A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK EventCam App. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive information. The attacker can exploit this weakness to eavesdrop on the communication between the EventCam App and the Client, and potentially manipulate the data being transmitted.

CVE-2023-31409 sick vulnerability CVSS: 0 15 May 2023, 11:15 UTC

Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an remote attacker to influence the availability of the webserver by invocing a Slowloris style attack via HTTP requests.

CVE-2023-31408 sick vulnerability CVSS: 0 15 May 2023, 11:15 UTC

Cleartext Storage of Sensitive Information in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to potentially steal user credentials that are stored in the user’s browsers local storage via cross-site-scripting attacks.

CVE-2023-23450 sick vulnerability CVSS: 0 15 May 2023, 11:15 UTC

Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to use a password hash instead of an actual password to login to a valid user account via the REST interface.

CVE-2023-23449 sick vulnerability CVSS: 0 15 May 2023, 11:15 UTC

Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames by analyzing challenge responses from the server via the REST interface.

CVE-2023-23448 sick vulnerability CVSS: 0 15 May 2023, 11:15 UTC

Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis of source code.

CVE-2023-23447 sick vulnerability CVSS: 0 15 May 2023, 11:15 UTC

Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to influence the availability of the webserver by invocing several open file requests via the REST interface.

CVE-2023-23446 sick vulnerability CVSS: 0 15 May 2023, 11:15 UTC

Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to download files by using a therefore unpriviledged account via the REST interface.

CVE-2023-23445 sick vulnerability CVSS: 0 15 May 2023, 11:15 UTC

Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to gain unauthorized access to data fields by using a therefore unpriviledged account via the REST interface.

CVE-2023-23444 sick vulnerability CVSS: 0 12 May 2023, 13:15 UTC

Missing Authentication for Critical Function in SICK Flexi Classic and Flexi Soft Gateways with Partnumbers 1042193, 1042964, 1044078, 1044072, 1044073, 1044074, 1099830, 1099832, 1127717, 1069070, 1112296, 1051432, 1102420, 1127487, 1121596, 1121597 allows an unauthenticated remote attacker to influence the availability of the device by changing the IP settings of the device via broadcasted UDP packets.

CVE-2023-23451 sick vulnerability CVSS: 0 19 Apr 2023, 23:15 UTC

The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN1 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN3S04 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN4 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK FX0-GENT00000 FLEXISOFT EIP GATEW. with serial number <=2311xxxx with Firmware <=V2.11.0, SICK FX0-GMOD00000 FLEXISOFT MOD GATEW. with serial number <=2311xxxx with Firmware <=V2.11.0, SICK FX0-GPNT00000 FLEXISOFT PNET GATEW. with serial number <=2311xxxx with Firmware <=V2.12.0, SICK FX0-GENT00030 FLEXISOFT EIP GATEW.V2 with serial number <=2311xxxx all Firmware versions, SICK FX0-GPNT00030 FLEXISOFT PNET GATEW.V2 with serial number <=2311xxxx all Firmware versions and SICK FX0-GMOD00010 FLEXISOFT MOD GW with serial number <=2311xxxx with Firmware <=V2.11.0 all have Telnet enabled by factory default. No password is set in the default configuration.

CVE-2023-23453 sick vulnerability CVSS: 0 20 Feb 2023, 23:15 UTC

Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.

CVE-2023-23452 sick vulnerability CVSS: 0 20 Feb 2023, 23:15 UTC

Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.

CVE-2022-47377 sick vulnerability CVSS: 0 16 Dec 2022, 15:15 UTC

Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase in their privileges on the system and thereby affecting the confidentiality integrity and availability of the system. An attacker can expect repeatable success by exploiting the vulnerability. The recommended solution is to update the firmware to a version >= 1.13.4 as soon as possible (available in SICK Support Portal).

CVE-2022-46834 sick vulnerability CVSS: 0 13 Dec 2022, 16:15 UTC

Use of a Broken or Risky Cryptographic Algorithm in SICK RFU65x firmware version < v2.21 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encryption via the SSH interface. The patch and installation procedure for the firmware update is available from the responsible SICK customer contact person.

CVE-2022-46833 sick vulnerability CVSS: 0 13 Dec 2022, 16:15 UTC

Use of a Broken or Risky Cryptographic Algorithm in SICK RFU63x firmware version < v2.21 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encryption via the SSH interface. The patch and installation procedure for the firmware update is available from the responsible SICK customer contact person.

CVE-2022-46832 sick vulnerability CVSS: 0 13 Dec 2022, 16:15 UTC

Use of a Broken or Risky Cryptographic Algorithm in SICK RFU62x firmware version < 2.21 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encryption via the SSH interface. The patch and installation procedure for the firmware update is available from the responsible SICK customer contact person.

CVE-2022-27581 sick vulnerability CVSS: 0 13 Dec 2022, 16:15 UTC

Use of a Broken or Risky Cryptographic Algorithm in SICK RFU61x firmware version <v2.25 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encryption via the SSH interface. The patch and installation procedure for the firmware update is available from the responsible SICK customer contact person.

CVE-2022-43990 sick vulnerability CVSS: 0 01 Nov 2022, 21:15 UTC

Password recovery vulnerability in SICK SIM1012 Partnumber 1098146 with firmware version <2.2.0 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase in their privileges on the system and thereby affecting the confidentiality integrity and availability of the system. An attacker can expect repeatable success by exploiting the vulnerability. The recommended solution is to update the firmware to a version >= 2.2.0 as soon as possible (available in SICK Support Portal).

CVE-2022-43989 sick vulnerability CVSS: 0 01 Nov 2022, 21:15 UTC

Password recovery vulnerability in SICK SIM2x00 (ARM) Partnumber 1092673 and 1081902 with firmware version < 1.2.0 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase in their privileges on the system and thereby affecting the confidentiality integrity and availability of the system. An attacker can expect repeatable success by exploiting the vulnerability. The recommended solution is to update the firmware to a version >= 1.2.0 as soon as possible (available in SICK Support Portal).

CVE-2022-27586 sick vulnerability CVSS: 0 01 Nov 2022, 21:15 UTC

Password recovery vulnerability in SICK SIM1004 Partnumber 1098148 with firmware version <2.0.0 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase in their privileges on the system and thereby affecting the confidentiality integrity and availability of the system. An attacker can expect repeatable success by exploiting the vulnerability. The recommended solution is to update the firmware to a version >= 2.0.0 as soon as possible (available in SICK Support Portal).

CVE-2022-27585 sick vulnerability CVSS: 0 01 Nov 2022, 21:15 UTC

Password recovery vulnerability in SICK SIM1000 FX Partnumber 1097816 and 1097817 with firmware version <1.6.0 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase in their privileges on the system and thereby affecting the confidentiality integrity and availability of the system. An attacker can expect repeatable success by exploiting the vulnerability. The recommended solution is to update the firmware to a version >= 1.6.0 as soon as possible (available in SICK Support Portal).

CVE-2022-27584 sick vulnerability CVSS: 0 01 Nov 2022, 21:15 UTC

Password recovery vulnerability in SICK SIM2000ST Partnumber 1080579 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase in their privileges on the system and thereby affecting the confidentiality integrity and availability of the system. An attacker can expect repeatable success by exploiting the vulnerability. The firmware versions <=1.7.0 allow to optionally disable device configuration over the network interfaces. Please make sure that you apply general security practices when operating the SIM2000ST. A fix is planned but not yet scheduled.

CVE-2022-27582 sick vulnerability CVSS: 0 01 Nov 2022, 21:15 UTC

Password recovery vulnerability in SICK SIM4000 (PPC) Partnumber 1078787 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase in their privileges on the system and thereby affecting the confidentiality integrity and availability of the system. An attacker can expect repeatable success by exploiting the vulnerability. The firmware versions <=1.10.1 allow to optionally disable device configuration over the network interfaces. Please make sure that you apply general security practices when operating the SIM4000. A fix is planned but not yet scheduled.

CVE-2022-27583 sick vulnerability CVSS: 0 31 Oct 2022, 20:15 UTC

A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2 running an affected firmware version to potentially impact the availability of the FlexiCompact.

CVE-2022-27580 sick vulnerability CVSS: 0 19 Jul 2022, 16:15 UTC

A deserialization vulnerability in a .NET framework class used and not properly checked by Safety Designer all versions up to and including 1.11.0 allows an attacker to craft malicious project files. Opening/importing such a malicious project file would execute arbitrary code with the privileges of the current user when opened or imported by the Safety Designer. This compromises confidentiality integrity and availability. For the attack to succeed a user must manually open a malicious project file.

CVE-2022-27579 sick vulnerability CVSS: 0 19 Jul 2022, 16:15 UTC

A deserialization vulnerability in a .NET framework class used and not properly checked by Flexi Soft Designer in all versions up to and including 1.9.4 SP1 allows an attacker to craft malicious project files. Opening/importing such a malicious project file would execute arbitrary code with the privileges of the current user when opened or imported by the Flexi Soft Designer. This compromises confidentiality integrity and availability. For the attack to succeed a user must manually open a malicious project file.

CVE-2021-32504 sick vulnerability CVSS: 0 19 Jul 2022, 15:15 UTC

Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users only. A malicious attacker could use this sensitive information’s to launch further attacks on the system.

CVE-2022-27578 sick vulnerability CVSS: 4.6 11 Apr 2022, 20:15 UTC

An attacker can perform a privilege escalation through the SICK OEE if the application is installed in a directory where non authenticated or low privilege users can modify its content.

CVE-2022-27577 sick vulnerability CVSS: 6.4 11 Apr 2022, 20:15 UTC

The vulnerability in the MSC800 in all versions before 4.15 allows for an attacker to predict the TCP initial sequence number. When the TCP sequence is predictable, an attacker can send packets that are forged to appear to come from a trusted computer. These forged packets could compromise services on the MSC800. SICK has released a new firmware version of the SICK MSC800 and recommends updating to the newest version.

CVE-2021-32503 sick vulnerability CVSS: 4.0 01 Apr 2022, 23:15 UTC

Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users only. A malicious attacker could use this sensitive information’s to launch further attacks on the system.

CVE-2021-32496 sick vulnerability CVSS: 3.5 28 Jun 2021, 12:15 UTC

SICK Visionary-S CX up version 5.21.2.29154R are vulnerable to an Inadequate Encryption Strength vulnerability concerning the internal SSH interface solely used by SICK for recovering returned devices. The use of weak ciphers make it easier for an attacker to break the security that protects information transmitted from the client to the SSH server, assuming the attacker has access to the network on which the device is connected. This can increase the risk that encryption will be compromised, leading to the exposure of sensitive user information and man-in-the-middle attacks.

CVE-2020-2075 sick vulnerability CVSS: 5.0 31 Aug 2020, 18:15 UTC

Platform mechanism AutoIP allows remote attackers to reboot the device via a crafted packet in SICK AG solutions Bulkscan LMS111, Bulkscan LMS511, CLV62x – CLV65x, ICR890-3, LMS10x, LMS11x, LMS15x, LMS12x, LMS13x, LMS14x, LMS5xx, LMS53x, MSC800, RFH.

CVE-2020-2078 sick vulnerability CVSS: 4.0 29 Jul 2020, 14:15 UTC

Passwords are stored in plain text within the configuration of SICK Package Analytics software up to and including V04.1.1. An authorized attacker could access these stored plaintext credentials and gain access to the ftp service. Storing a password in plaintext allows attackers to easily gain access to systems, potentially compromising personal information or other sensitive information.

CVE-2020-2077 sick vulnerability CVSS: 5.0 29 Jul 2020, 14:15 UTC

SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions settings. An unauthorized attacker could read sensitive data from the system by querying for known files using the REST API directly.

CVE-2020-2076 sick vulnerability CVSS: 7.5 29 Jul 2020, 14:15 UTC

SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with the REST API. An attacker can send unauthorized requests, bypass current authentication controls presented by the application and could potentially write files without authentication.

CVE-2019-14753 sick vulnerability CVSS: 5.0 24 Sep 2019, 17:15 UTC

SICK FX0-GPNT00000 and FX0-GENT00000 devices through 3.4.0 have a Buffer Overflow

CVE-2019-10979 sick vulnerability CVSS: 7.5 01 Jul 2019, 21:15 UTC

SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password.