CVE-2023-23451

CRITICAL

SICK Flexi Classic and Flexi Soft Gateways - Unauthenticated Remote Access via Default Telnet Configuration

Title source: llm
STIX 2.1

Description

The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN1 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN3S04 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN4 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK FX0-GENT00000 FLEXISOFT EIP GATEW. with serial number <=2311xxxx with Firmware <=V2.11.0, SICK FX0-GMOD00000 FLEXISOFT MOD GATEW. with serial number <=2311xxxx with Firmware <=V2.11.0, SICK FX0-GPNT00000 FLEXISOFT PNET GATEW. with serial number <=2311xxxx with Firmware <=V2.12.0, SICK FX0-GENT00030 FLEXISOFT EIP GATEW.V2 with serial number <=2311xxxx all Firmware versions, SICK FX0-GPNT00030 FLEXISOFT PNET GATEW.V2 with serial number <=2311xxxx all Firmware versions and SICK FX0-GMOD00010 FLEXISOFT MOD GW with serial number <=2311xxxx with Firmware <=V2.11.0 all have Telnet enabled by factory default. No password is set in the default configuration.

References (1)

Core 1
Core References
Vendor Advisory
https://sick.com/psirt

Scores

CVSS v3 9.8
EPSS 0.0062
EPSS Percentile 45.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306 CWE-477
Status published
Products (10)
sick/fx0-gent00000_firmware < 2.11.0
sick/fx0-gent00030_firmware
sick/fx0-gmod00000_firmware < 2.11.0
sick/fx0-gmod00010_firmware < 2.11.0
sick/fx0-gpnt00000_firmware < 2.12.0
sick/fx0-gpnt00030_firmware
sick/ue410-en1_firmware
sick/ue410-en3_firmware
sick/ue410-en3s04_firmware
sick/ue410-en4_firmware
Published Apr 19, 2023
Tracked Since Feb 18, 2026