Description
The product is vulnerable to pass-the-hash attacks in combination with hardcoded credentials of hidden user levels. This means that an attacker can log in with the hidden user levels and gain full access to the device.
References (6)
Scores
CVSS v3
9.0
EPSS
0.0036
EPSS Percentile
58.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-912
Status
published
Products (3)
SICK AG/SICK InspectorP61x
< <5.0.0
SICK AG/SICK InspectorP62x
< <5.0.0
SICK AG/TiM3xx
< <5.10.0
Published
Dec 06, 2024
Tracked Since
Feb 18, 2026