CVE-2023-4420

CRITICAL

SICK LMS5xx Firmware - Unauthenticated Sensitive Data Exposure via Missing TLS Encryption

Title source: llm
STIX 2.1

Description

A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK LMS5xx. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive information. The attacker can exploit this weakness to eavesdrop on the communication between the LMS5xx and the Client, and potentially manipulate the data being transmitted.

References (3)

Core 3
Core References
Vendor Advisory issue-tracking
https://sick.com/psirt

Scores

CVSS v3 9.8
EPSS 0.0024
EPSS Percentile 15.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-311
Status published
Products (4)
sick/lms500_firmware
sick/lms511_firmware
sick/lms531_firmware
SICK AG/LMS5xx all firmware versions
Published Aug 24, 2023
Tracked Since Feb 18, 2026