CVE-2023-31411

CRITICAL

sick_eventcam_app - Unauthenticated Configuration Modification via API

Title source: llm
STIX 2.1

Description

A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication. The lack of authentication in the API allows the attacker to potentially compromise the functionality of the EventCam App.

References (3)

Core 3
Core References
Vendor Advisory issue-tracking
https://sick.com/psirt

Scores

CVSS v3 9.8
EPSS 0.0090
EPSS Percentile 55.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (2)
sick/sick_eventcam_app
SICK AG/EventCam App all versions
Published Jun 19, 2023
Tracked Since Feb 18, 2026