CVE-2025-27593

CRITICAL

SDD Device Drivers - Code Injection

Title source: llm
STIX 2.1

Description

The product can be used to distribute malicious code using SDD Device Drivers due to missing download verification checks, leading to code execution on target systems.

References (7)

Core 7
Core References
Various Sources x_sick psirt website
https://sick.com/psirt
Third Party Advisory, US Government Resource x_ics-cert recommended practices on industrial security
https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Various Sources x_cvss v3.1 calculator
https://www.first.org/cvss/calculator/3.1

Scores

CVSS v3 9.3
EPSS 0.0039
EPSS Percentile 30.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-494
Status published
Products (1)
SICK AG/SICK DL100-2xxxxxxx all versions
Published Mar 14, 2025
Tracked Since Feb 18, 2026