CVE-2023-23446

HIGH

SICK FTMg AIR FLOW SENSOR Firmware < 2.0 - Unauthenticated Arbitrary File Read via REST Interface

Title source: llm
STIX 2.1

Description

Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to download files by using a therefore unpriviledged account via the REST interface.

References (3)

Core 3
Core References
Vendor Advisory issue-tracking
https://sick.com/psirt

Scores

CVSS v3 7.5
EPSS 0.0089
EPSS Percentile 54.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-284 CWE-863
Status published
Products (14)
sick/ftmg-esd15axx_firmware < 2.0
sick/ftmg-esd20axx_firmware < 2.0
sick/ftmg-esd25axx_firmware < 2.0
sick/ftmg-esn40sxx_firmware < 2.0
sick/ftmg-esn50sxx_firmware < 2.0
sick/ftmg-esr40sxx_firmware < 2.0
sick/ftmg-esr50sxx_firmware < 2.0
SICK AG/SICK FTMG-ESD15AXX AIR FLOW SENSOR < v3.0.0.131.Release
SICK AG/SICK FTMG-ESD20AXX AIR FLOW SENSOR < v3.0.0.131.Release
SICK AG/SICK FTMG-ESD25AXX AIR FLOW SENSOR < v3.0.0.131.Release
... and 4 more
Published May 15, 2023
Tracked Since Feb 18, 2026