HIGH
Improper Restriction of Excessive Authentication Attempts in the SICK ICR890-4
Published Jul 10, 2023
7.5
HIGHCVSS 3.1
EPSS 0.90%
Description
Improper Restriction of Excessive Authentication Attempts in the SICK ICR890-4 could allow a remote attacker to brute-force user credentials.
Affected products
-
- Version 0StatusaffectedConstraints<2.5.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Sick AG | n/a | affected |
|
AND
- < 2.5.0
-
- Version 0StatusaffectedConstraints<2.5.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Sick AG | n/a | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
The recommended solution is to update the firmware to a version >= V2.5.0 as soon as possible.
Weaknesses (1)
References (3)
- https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.json x_csafVendor Advisory
- https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.pdf vendor-advisoryVendor Advisory
- https://sick.com/psirt issue-trackingProduct
| Link | Providers | Tags |
|---|---|---|
| https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.json | x_csafVendor Advisory | |
| https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.pdf | vendor-advisoryVendor Advisory | |
| https://sick.com/psirt | issue-trackingProduct |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner SICK AG
Published Jul 10, 2023
Updated Jun 1, 2026
Reserved Jun 15, 2023
Link CVE-2023-35697
CISA Vulnrichment
Updated Nov 12, 2024