CVE-2019-10979
CRITICALSICK MSC800 Firmware < 4.0 - Use of Hard-coded Credentials
Title source: llmDescription
SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/108924
Third Party Advisory, US Government Resource x_refsource_misc
https://www.us-cert.gov/ics/advisories/icsa-19-178-04
Various Sources x_refsource_confirm
https://www.sick.com/de/en/service-and-support/the-sick-product-security-incident-response-team-sick-psirt/w/psirt/#advisories
Scores
CVSS v3
9.8
EPSS
0.0338
EPSS Percentile
87.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-798
Status
published
Products (1)
sick/msc800_firmware
< 4.0
Published
Jul 01, 2019
Tracked Since
Feb 18, 2026