CVE-2023-23445

HIGH

SICK FTMg AIR FLOW SENSOR Firmware < 2.0 - Unauthenticated Improper Access Control via REST Interface

Title source: llm
STIX 2.1

Description

Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to gain unauthorized access to data fields by using a therefore unpriviledged account via the REST interface.

References (3)

Core 3
Core References
Vendor Advisory issue-tracking
https://sick.com/psirt

Scores

CVSS v3 7.5
EPSS 0.0066
EPSS Percentile 46.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-284 CWE-863
Status published
Products (14)
sick/ftmg-esd15axx_firmware < 2.0
sick/ftmg-esd20axx_firmware < 2.0
sick/ftmg-esd25axx_firmware < 2.0
sick/ftmg-esn40sxx_firmware < 2.0
sick/ftmg-esn50sxx_firmware < 2.0
sick/ftmg-esr40sxx_firmware < 2.0
sick/ftmg-esr50sxx_firmware < 2.0
SICK AG/SICK FTMG-ESD15AXX AIR FLOW SENSOR all firmware versions
SICK AG/SICK FTMG-ESD20AXX AIR FLOW SENSOR all firmware versions
SICK AG/SICK FTMG-ESD25AXX AIR FLOW SENSOR all firmware versions
... and 4 more
Published May 15, 2023
Tracked Since Feb 18, 2026