CVE-2023-23450

MEDIUM

SICK FTMg AIR FLOW SENSOR Firmware < 2.0 - Unauthenticated Authentication Bypass via REST Interface

Title source: llm
STIX 2.1

Description

Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to use a password hash instead of an actual password to login to a valid user account via the REST interface.

References (3)

Core 3
Core References
Vendor Advisory issue-tracking
https://sick.com/psirt

Scores

CVSS v3 6.2
EPSS 0.0071
EPSS Percentile 48.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287 CWE-836
Status published
Products (14)
sick/ftmg-esd15axx_firmware < 2.0
sick/ftmg-esd20axx_firmware < 2.0
sick/ftmg-esd25axx_firmware < 2.0
sick/ftmg-esn40sxx_firmware < 2.0
sick/ftmg-esn50sxx_firmware < 2.0
sick/ftmg-esr40sxx_firmware < 2.0
sick/ftmg-esr50sxx_firmware < 2.0
SICK AG/SICK FTMG-ESD15AXX AIR FLOW SENSOR all firmware versions
SICK AG/SICK FTMG-ESD20AXX AIR FLOW SENSOR all firmware versions
SICK AG/SICK FTMG-ESD25AXX AIR FLOW SENSOR all firmware versions
... and 4 more
Published May 15, 2023
Tracked Since Feb 18, 2026