Back

HIGH

Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing

Published Jul 10, 2023

Description

Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endpoints.

Affected products

Remediation

Vendor solution

The recommended solution is to update the firmware to a version >= V2.5.0 as soon as possible.

Metrics

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner SICK AG
Published Jul 10, 2023
Updated Jun 1, 2026
Reserved Jun 15, 2023
CISA Vulnrichment
Updated Nov 12, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a