Записи SICK
130 опубликованных записей вендора sick.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 8,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-306 Missing Authentication for Critical Function15
- CWE-284 Improper Access Control7
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm7
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-319 Cleartext Transmission of Sensitive Information5
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
130 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2019-10979Эксплойта нет | SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password.sick · msc800 firmware · CWE-798 | Критическая9,8 | — | 3,4 % | 1 июл. 2019 г. |
39Наблюдать | CVE-2022-27582Эксплойта нет | Password recovery vulnerability in SICK SIM4000 (PPC) Partnumber 1078787 allows an unprivileged remote attacker to gain access to the userlesick · sim2000 firmware · CWE-306 | Критическая9,8 | — | 1,3 % | 1 нояб. 2022 г. |
39Наблюдать | CVE-2022-27584Эксплойта нет | Password recovery vulnerability in SICK SIM2000ST Partnumber 1080579 allows an unprivileged remote attacker to gain access to the userlevel sick · sim2000st firmware · CWE-306 | Критическая9,8 | — | 1,3 % | 1 нояб. 2022 г. |
39Наблюдать | CVE-2022-27585Эксплойта нет | Password recovery vulnerability in SICK SIM1000 FX Partnumber 1097816 and 1097817 with firmware version <1.6.0 allows an unprivileged remotesick · sim1000 fx firmware · CWE-306 | Критическая9,8 | — | 1,3 % | 1 нояб. 2022 г. |
39Наблюдать | CVE-2022-27586Эксплойта нет | Password recovery vulnerability in SICK SIM1004 Partnumber 1098148 with firmware version <2.0.0 allows an unprivileged remote attacker to gasick · sim1004-0p0g311 firmware · CWE-306 | Критическая9,8 | — | 1,3 % | 1 нояб. 2022 г. |
39Наблюдать | CVE-2020-2076Эксплойта нет | SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with sick · package analytics · CWE-306 | Критическая9,8 | — | 1,3 % | 29 июл. 2020 г. |
39Наблюдать | CVE-2023-23452Эксплойта нет | Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to sick · fx0-gpnt00000 firmware · CWE-306 | Критическая9,8 | — | 1,1 % | 20 февр. 2023 г. |
39Наблюдать | CVE-2023-23453Эксплойта нет | Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to sick · fx0-gent00010 firmware · CWE-306 | Критическая9,8 | — | 1,1 % | 20 февр. 2023 г. |
39Наблюдать | CVE-2023-31411Эксплойта нет | A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication.sick · sick eventcam app · CWE-306 | Критическая9,8 | — | 0,9 % | 19 июн. 2023 г. |
39Наблюдать | CVE-2022-47377Эксплойта нет | Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker tosick · sim2000 firmware · CWE-306 | Критическая9,8 | — | 0,9 % | 16 дек. 2022 г. |
39Наблюдать | CVE-2023-23450Эксплойта нет | Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114sick · ftmg-esd20axx firmware · CWE-836 | Критическая9,8 | — | 0,7 % | 15 мая 2023 г. |
39Наблюдать | CVE-2023-5288Эксплойта нет | A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings.sick · sim1012-0p0g200 firmware · CWE-284 | Критическая9,8 | — | 0,6 % | 29 сент. 2023 г. |
39Наблюдать | CVE-2023-43696Эксплойта нет | Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous accesick · apu0200 firmware · CWE-284 | Критическая9,8 | — | 0,6 % | 9 окт. 2023 г. |
39Наблюдать | CVE-2023-23451Эксплойта нет | The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW.sick · ue410-en3 firmware · CWE-477 | Критическая9,8 | — | 0,6 % | 19 апр. 2023 г. |
39Наблюдать | CVE-2025-49182Эксплойта нет | Credential disclosuresick · media server · CWE-540 | Критическая9,8 | — | 0,6 % | 12 июн. 2025 г. |
39Наблюдать | CVE-2025-49195Эксплойта нет | No protection against brute-force attackssick · media server · CWE-307 | Критическая9,8 | — | 0,5 % | 12 июн. 2025 г. |
39Наблюдать | CVE-2025-58587Эксплойта нет | Improper Restriction of Excessive Authentication Attemptssick · baggage analytics · CWE-307 | Критическая9,8 | — | 0,5 % | 6 окт. 2025 г. |
39Наблюдать | CVE-2025-59461Эксплойта нет | API does not require authenticationsick · tloc100-100 firmware · CWE-862 | Критическая9,8 | — | 0,5 % | 27 окт. 2025 г. |
39Наблюдать | CVE-2025-49199Эксплойта нет | Backup files can be modified and uploadedsick · field analytics · CWE-345 | Критическая9,8 | — | 0,3 % | 12 июн. 2025 г. |
36Наблюдать | CVE-2022-27577Эксплойта нет | The vulnerability in the MSC800 in all versions before 4.15 allows for an attacker to predict the TCP initial sequence number.sick · msc800 firmware · CWE-342 | Критическая9,1 | — | 1,4 % | 11 апр. 2022 г. |
36Наблюдать | CVE-2024-10025Эксплойта нет | Vulnerability in SICK CLV6xx, SICK Lector6xx and SICK RFx6xxsick ag · sick clv6xx · CWE-798 | Критическая9,1 | — | 0,8 % | 17 окт. 2024 г. |
36Наблюдать | CVE-2022-27583Эксплойта нет | A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2 running an affectedsick · flx3-cpuc1 firmware · CWE-285 | Критическая9,1 | — | 0,6 % | 31 окт. 2022 г. |
36Наблюдать | CVE-2026-22908Эксплойта нет | Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity sick · tdc-x401gl firmware · CWE-266 | Критическая9,1 | — | 0,6 % | 15 янв. 2026 г. |
36Наблюдать | CVE-2024-10773Эксплойта нет | SICK InspectorP61x, SICK InspectorP62x and SICK TiM3xx are vulnerable for pass-the-hash attackssick ag · sick inspectorp61x · CWE-912 | Критическая9,0 | — | 0,6 % | 6 дек. 2024 г. |
36Наблюдать | CVE-2026-22909Эксплойта нет | Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, sick · tdc-x401gl firmware · CWE-284 | Критическая9,1 | — | 0,6 % | 15 янв. 2026 г. |
- CVE-2019-1097940В плане
SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %sick · msc800 firmware1 июл. 2019 г.
- CVE-2022-2758239Наблюдать
Password recovery vulnerability in SICK SIM4000 (PPC) Partnumber 1078787 allows an unprivileged remote attacker to gain access to the userle
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sick · sim2000 firmware1 нояб. 2022 г.
- CVE-2022-2758439Наблюдать
Password recovery vulnerability in SICK SIM2000ST Partnumber 1080579 allows an unprivileged remote attacker to gain access to the userlevel
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sick · sim2000st firmware1 нояб. 2022 г.
- CVE-2022-2758539Наблюдать
Password recovery vulnerability in SICK SIM1000 FX Partnumber 1097816 and 1097817 with firmware version <1.6.0 allows an unprivileged remote
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sick · sim1000 fx firmware1 нояб. 2022 г.
- CVE-2022-2758639Наблюдать
Password recovery vulnerability in SICK SIM1004 Partnumber 1098148 with firmware version <2.0.0 allows an unprivileged remote attacker to ga
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sick · sim1004-0p0g311 firmware1 нояб. 2022 г.
- CVE-2020-207639Наблюдать
SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sick · package analytics29 июл. 2020 г.
- CVE-2023-2345239Наблюдать
Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sick · fx0-gpnt00000 firmware20 февр. 2023 г.
- CVE-2023-2345339Наблюдать
Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sick · fx0-gent00010 firmware20 февр. 2023 г.
- CVE-2023-3141139Наблюдать
A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sick · sick eventcam app19 июн. 2023 г.
- CVE-2022-4737739Наблюдать
Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker to
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sick · sim2000 firmware16 дек. 2022 г.
- CVE-2023-2345039Наблюдать
Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sick · ftmg-esd20axx firmware15 мая 2023 г.
- CVE-2023-528839Наблюдать
A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sick · sim1012-0p0g200 firmware29 сент. 2023 г.
- CVE-2023-4369639Наблюдать
Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous acce
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sick · apu0200 firmware9 окт. 2023 г.
- CVE-2023-2345139Наблюдать
The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sick · ue410-en3 firmware19 апр. 2023 г.
- CVE-2025-4918239Наблюдать
Credential disclosure
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sick · media server12 июн. 2025 г.
- CVE-2025-4919539Наблюдать
No protection against brute-force attacks
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sick · media server12 июн. 2025 г.
- CVE-2025-5858739Наблюдать
Improper Restriction of Excessive Authentication Attempts
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %sick · baggage analytics6 окт. 2025 г.
- CVE-2025-5946139Наблюдать
API does not require authentication
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %sick · tloc100-100 firmware27 окт. 2025 г.
- CVE-2025-4919939Наблюдать
Backup files can be modified and uploaded
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %sick · field analytics12 июн. 2025 г.
- CVE-2022-2757736Наблюдать
The vulnerability in the MSC800 in all versions before 4.15 allows for an attacker to predict the TCP initial sequence number.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %sick · msc800 firmware11 апр. 2022 г.
- CVE-2024-1002536Наблюдать
Vulnerability in SICK CLV6xx, SICK Lector6xx and SICK RFx6xx
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %sick ag · sick clv6xx17 окт. 2024 г.
- CVE-2022-2758336Наблюдать
A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2 running an affected
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %sick · flx3-cpuc1 firmware31 окт. 2022 г.
- CVE-2026-2290836Наблюдать
Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %sick · tdc-x401gl firmware15 янв. 2026 г.
- CVE-2024-1077336Наблюдать
SICK InspectorP61x, SICK InspectorP62x and SICK TiM3xx are vulnerable for pass-the-hash attacks
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %sick ag · sick inspectorp61x6 дек. 2024 г.
- CVE-2026-2290936Наблюдать
Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications,
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %sick · tdc-x401gl firmware15 янв. 2026 г.