SICK records
130 published records for vendor sick.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 8.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-306 Missing Authentication for Critical Function15
- CWE-284 Improper Access Control7
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm7
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-319 Cleartext Transmission of Sensitive Information5
The weakness classes this vendor ships most often: where to look.
CWEAll records
130 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-10979No exploit | SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password.sick · msc800 firmware · CWE-798 | Critical9.8 | — | 3.4% | Jul 1, 2019 |
39Monitor | CVE-2022-27582No exploit | Password recovery vulnerability in SICK SIM4000 (PPC) Partnumber 1078787 allows an unprivileged remote attacker to gain access to the userlesick · sim2000 firmware · CWE-306 | Critical9.8 | — | 1.3% | Nov 1, 2022 |
39Monitor | CVE-2022-27584No exploit | Password recovery vulnerability in SICK SIM2000ST Partnumber 1080579 allows an unprivileged remote attacker to gain access to the userlevel sick · sim2000st firmware · CWE-306 | Critical9.8 | — | 1.3% | Nov 1, 2022 |
39Monitor | CVE-2022-27585No exploit | Password recovery vulnerability in SICK SIM1000 FX Partnumber 1097816 and 1097817 with firmware version <1.6.0 allows an unprivileged remotesick · sim1000 fx firmware · CWE-306 | Critical9.8 | — | 1.3% | Nov 1, 2022 |
39Monitor | CVE-2022-27586No exploit | Password recovery vulnerability in SICK SIM1004 Partnumber 1098148 with firmware version <2.0.0 allows an unprivileged remote attacker to gasick · sim1004-0p0g311 firmware · CWE-306 | Critical9.8 | — | 1.3% | Nov 1, 2022 |
39Monitor | CVE-2020-2076No exploit | SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with sick · package analytics · CWE-306 | Critical9.8 | — | 1.3% | Jul 29, 2020 |
39Monitor | CVE-2023-23452No exploit | Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to sick · fx0-gpnt00000 firmware · CWE-306 | Critical9.8 | — | 1.1% | Feb 20, 2023 |
39Monitor | CVE-2023-23453No exploit | Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to sick · fx0-gent00010 firmware · CWE-306 | Critical9.8 | — | 1.1% | Feb 20, 2023 |
39Monitor | CVE-2023-31411No exploit | A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication.sick · sick eventcam app · CWE-306 | Critical9.8 | — | 0.9% | Jun 19, 2023 |
39Monitor | CVE-2022-47377No exploit | Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker tosick · sim2000 firmware · CWE-306 | Critical9.8 | — | 0.9% | Dec 16, 2022 |
39Monitor | CVE-2023-23450No exploit | Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114sick · ftmg-esd20axx firmware · CWE-836 | Critical9.8 | — | 0.7% | May 15, 2023 |
39Monitor | CVE-2023-5288No exploit | A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings.sick · sim1012-0p0g200 firmware · CWE-284 | Critical9.8 | — | 0.6% | Sep 29, 2023 |
39Monitor | CVE-2023-43696No exploit | Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous accesick · apu0200 firmware · CWE-284 | Critical9.8 | — | 0.6% | Oct 9, 2023 |
39Monitor | CVE-2023-23451No exploit | The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW.sick · ue410-en3 firmware · CWE-477 | Critical9.8 | — | 0.6% | Apr 19, 2023 |
39Monitor | CVE-2025-49182No exploit | Credential disclosuresick · media server · CWE-540 | Critical9.8 | — | 0.6% | Jun 12, 2025 |
39Monitor | CVE-2025-49195No exploit | No protection against brute-force attackssick · media server · CWE-307 | Critical9.8 | — | 0.5% | Jun 12, 2025 |
39Monitor | CVE-2025-58587No exploit | Improper Restriction of Excessive Authentication Attemptssick · baggage analytics · CWE-307 | Critical9.8 | — | 0.5% | Oct 6, 2025 |
39Monitor | CVE-2025-59461No exploit | API does not require authenticationsick · tloc100-100 firmware · CWE-862 | Critical9.8 | — | 0.5% | Oct 27, 2025 |
39Monitor | CVE-2025-49199No exploit | Backup files can be modified and uploadedsick · field analytics · CWE-345 | Critical9.8 | — | 0.3% | Jun 12, 2025 |
36Monitor | CVE-2022-27577No exploit | The vulnerability in the MSC800 in all versions before 4.15 allows for an attacker to predict the TCP initial sequence number.sick · msc800 firmware · CWE-342 | Critical9.1 | — | 1.4% | Apr 11, 2022 |
36Monitor | CVE-2024-10025No exploit | Vulnerability in SICK CLV6xx, SICK Lector6xx and SICK RFx6xxsick ag · sick clv6xx · CWE-798 | Critical9.1 | — | 0.8% | Oct 17, 2024 |
36Monitor | CVE-2022-27583No exploit | A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2 running an affectedsick · flx3-cpuc1 firmware · CWE-285 | Critical9.1 | — | 0.6% | Oct 31, 2022 |
36Monitor | CVE-2026-22908No exploit | Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity sick · tdc-x401gl firmware · CWE-266 | Critical9.1 | — | 0.6% | Jan 15, 2026 |
36Monitor | CVE-2024-10773No exploit | SICK InspectorP61x, SICK InspectorP62x and SICK TiM3xx are vulnerable for pass-the-hash attackssick ag · sick inspectorp61x · CWE-912 | Critical9.0 | — | 0.6% | Dec 6, 2024 |
36Monitor | CVE-2026-22909No exploit | Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, sick · tdc-x401gl firmware · CWE-284 | Critical9.1 | — | 0.6% | Jan 15, 2026 |
- CVE-2019-1097940Plan
SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password.
CriticalCVSS 9.8No exploitEPSS 3%sick · msc800 firmwareJul 1, 2019
- CVE-2022-2758239Monitor
Password recovery vulnerability in SICK SIM4000 (PPC) Partnumber 1078787 allows an unprivileged remote attacker to gain access to the userle
CriticalCVSS 9.8No exploitEPSS 1%sick · sim2000 firmwareNov 1, 2022
- CVE-2022-2758439Monitor
Password recovery vulnerability in SICK SIM2000ST Partnumber 1080579 allows an unprivileged remote attacker to gain access to the userlevel
CriticalCVSS 9.8No exploitEPSS 1%sick · sim2000st firmwareNov 1, 2022
- CVE-2022-2758539Monitor
Password recovery vulnerability in SICK SIM1000 FX Partnumber 1097816 and 1097817 with firmware version <1.6.0 allows an unprivileged remote
CriticalCVSS 9.8No exploitEPSS 1%sick · sim1000 fx firmwareNov 1, 2022
- CVE-2022-2758639Monitor
Password recovery vulnerability in SICK SIM1004 Partnumber 1098148 with firmware version <2.0.0 allows an unprivileged remote attacker to ga
CriticalCVSS 9.8No exploitEPSS 1%sick · sim1004-0p0g311 firmwareNov 1, 2022
- CVE-2020-207639Monitor
SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with
CriticalCVSS 9.8No exploitEPSS 1%sick · package analyticsJul 29, 2020
- CVE-2023-2345239Monitor
Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to
CriticalCVSS 9.8No exploitEPSS 1%sick · fx0-gpnt00000 firmwareFeb 20, 2023
- CVE-2023-2345339Monitor
Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to
CriticalCVSS 9.8No exploitEPSS 1%sick · fx0-gent00010 firmwareFeb 20, 2023
- CVE-2023-3141139Monitor
A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication.
CriticalCVSS 9.8No exploitEPSS 1%sick · sick eventcam appJun 19, 2023
- CVE-2022-4737739Monitor
Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker to
CriticalCVSS 9.8No exploitEPSS 1%sick · sim2000 firmwareDec 16, 2022
- CVE-2023-2345039Monitor
Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114
CriticalCVSS 9.8No exploitEPSS 1%sick · ftmg-esd20axx firmwareMay 15, 2023
- CVE-2023-528839Monitor
A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings.
CriticalCVSS 9.8No exploitEPSS 1%sick · sim1012-0p0g200 firmwareSep 29, 2023
- CVE-2023-4369639Monitor
Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous acce
CriticalCVSS 9.8No exploitEPSS 1%sick · apu0200 firmwareOct 9, 2023
- CVE-2023-2345139Monitor
The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW.
CriticalCVSS 9.8No exploitEPSS 1%sick · ue410-en3 firmwareApr 19, 2023
- CVE-2025-4918239Monitor
Credential disclosure
CriticalCVSS 9.8No exploitEPSS 1%sick · media serverJun 12, 2025
- CVE-2025-4919539Monitor
No protection against brute-force attacks
CriticalCVSS 9.8No exploitEPSS 1%sick · media serverJun 12, 2025
- CVE-2025-5858739Monitor
Improper Restriction of Excessive Authentication Attempts
CriticalCVSS 9.8No exploitEPSS 0%sick · baggage analyticsOct 6, 2025
- CVE-2025-5946139Monitor
API does not require authentication
CriticalCVSS 9.8No exploitEPSS 0%sick · tloc100-100 firmwareOct 27, 2025
- CVE-2025-4919939Monitor
Backup files can be modified and uploaded
CriticalCVSS 9.8No exploitEPSS 0%sick · field analyticsJun 12, 2025
- CVE-2022-2757736Monitor
The vulnerability in the MSC800 in all versions before 4.15 allows for an attacker to predict the TCP initial sequence number.
CriticalCVSS 9.1No exploitEPSS 1%sick · msc800 firmwareApr 11, 2022
- CVE-2024-1002536Monitor
Vulnerability in SICK CLV6xx, SICK Lector6xx and SICK RFx6xx
CriticalCVSS 9.1No exploitEPSS 1%sick ag · sick clv6xxOct 17, 2024
- CVE-2022-2758336Monitor
A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2 running an affected
CriticalCVSS 9.1No exploitEPSS 1%sick · flx3-cpuc1 firmwareOct 31, 2022
- CVE-2026-2290836Monitor
Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity
CriticalCVSS 9.1No exploitEPSS 1%sick · tdc-x401gl firmwareJan 15, 2026
- CVE-2024-1077336Monitor
SICK InspectorP61x, SICK InspectorP62x and SICK TiM3xx are vulnerable for pass-the-hash attacks
CriticalCVSS 9.0No exploitEPSS 1%sick ag · sick inspectorp61xDec 6, 2024
- CVE-2026-2290936Monitor
Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications,
CriticalCVSS 9.1No exploitEPSS 1%sick · tdc-x401gl firmwareJan 15, 2026