HIGH · 8.2

CVE-2023-3271

Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endp...

Vulnerability Description

Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endpoints.

CVSS Score

8.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
SickIcr890-4 Firmware< 2.5.0
SickIcr890-4-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-3271?

CVE-2023-3271 is a vulnerability with a CVSS score of 8.2 (HIGH). Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endp...

How severe is CVE-2023-3271?

CVE-2023-3271 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-3271?

Check the references section above for vendor advisories and patch information. Affected products include: Sick Icr890-4 Firmware, Sick Icr890-4.