CVE-2023-4420

CRITICAL

Sick Lms531 Firmware - Missing Encryption

Title source: rule
STIX 2.1

Description

A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK LMS5xx. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive information. The attacker can exploit this weakness to eavesdrop on the communication between the LMS5xx and the Client, and potentially manipulate the data being transmitted.

Scores

CVSS v3 9.8
EPSS 0.0007
EPSS Percentile 20.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-311
Status published
Products (3)
sick/lms500_firmware
sick/lms511_firmware
sick/lms531_firmware
Published Aug 24, 2023
Tracked Since Feb 18, 2026