CVE-2023-23447

HIGH

SICK FTMg AIR FLOW SENSOR Firmware < 2.0 - Unauthenticated Denial of Service via REST Interface

Title source: llm
STIX 2.1

Description

Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to influence the availability of the webserver by invocing several open file requests via the REST interface.

References (3)

Core 3
Core References
Vendor Advisory issue-tracking
https://sick.com/psirt

Scores

CVSS v3 7.5
EPSS 0.0112
EPSS Percentile 61.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (14)
sick/ftmg-esd15axx_firmware < 2.0
sick/ftmg-esd20axx_firmware < 2.0
sick/ftmg-esd25axx_firmware < 2.0
sick/ftmg-esn40sxx_firmware < 2.0
sick/ftmg-esn50sxx_firmware < 2.0
sick/ftmg-esr40sxx_firmware < 2.0
sick/ftmg-esr50sxx_firmware < 2.0
SICK AG/SICK FTMG-ESD15AXX AIR FLOW SENSOR < v3.0.0.131.Release
SICK AG/SICK FTMG-ESD20AXX AIR FLOW SENSOR < v3.0.0.131.Release
SICK AG/SICK FTMG-ESD25AXX AIR FLOW SENSOR < v3.0.0.131.Release
... and 4 more
Published May 15, 2023
Tracked Since Feb 18, 2026