Loading HuntDB...

SICK AG

65 Products 43 CVEs

CVE Severity Distribution (All Time)

Critical
7
High
22
Medium
14
Low
0

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 9 CVEs

Recent CVEs

View all
CVE-2024-10776 HIGH 7 months, 3 weeks ago

Lua apps can be deployed, removed, started, reloaded or stopped without authorization via AppManager. This allows an attacker to remove legitimate ap…

CVE-2024-10774 HIGH 7 months, 3 weeks ago

Unauthenticated CROWN APIs allow access to critical functions. This leads to the accessibility of large parts of the web application without authenti…

CVE-2024-10773 CRITICAL 7 months, 3 weeks ago

The product is vulnerable to pass-the-hash attacks in combination with hardcoded credentials of hidden user levels. This means that an attacker can l…

CVE-2024-10772 HIGH 7 months, 3 weeks ago

Since the firmware update is not validated, an attacker can install modified firmware on the device. This has a high impact on the availabilty, integ…

CVE-2024-10771 HIGH 7 months, 3 weeks ago

Due to missing input validation during one step of the firmware update process, the product is vulnerable to remote code execution. With network acce…

CVE-2024-11022 MEDIUM 7 months, 3 weeks ago

The authentication process to the web server uses a challenge response procedure which inludes the nonce and additional information. This challenge c…

CVE-2024-11075 HIGH 8 months, 1 week ago

A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escal…

CVE-2024-10025 CRITICAL 9 months, 1 week ago

A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By exploiting these plaintext cre…

CVE-2024-8751 HIGH 10 months, 2 weeks ago

A vulnerability in the MSC800 allows an unauthenticated attacker to modify the product’s IP address over Sopas ET. This can lead to Denial of Servic…