CRITICAL · 9.8

CVE-2023-23452

Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously craf...

Vulnerability Description

Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SickFx0-Gpnt00000 Firmware3.04
SickFx0-Gpnt00000-
SickFx0-Gpnt00010 Firmware3.04
SickFx0-Gpnt00010-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-23452?

CVE-2023-23452 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously craf...

How severe is CVE-2023-23452?

CVE-2023-23452 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2023-23452?

Check the references section above for vendor advisories and patch information. Affected products include: Sick Fx0-Gpnt00000 Firmware, Sick Fx0-Gpnt00000, Sick Fx0-Gpnt00010 Firmware, Sick Fx0-Gpnt00010.