Lucene search

K
cve[email protected]CVE-2023-31412
HistoryAug 24, 2023 - 7:15 p.m.

CVE-2023-31412

2023-08-2419:15:33
CWE-916
web.nvd.nist.gov
8
lms5xx
weak hash
insecure
collision attacks
password retrieval
nvd

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.3%

The LMS5xx uses weak hash generation methods, resulting in the creation of insecure hashs. If an attacker manages to retrieve the hash, it could lead to collision attacks and the potential retrieval of the password.

Affected configurations

NVD
Node
sicklms531Match-
AND
sicklms531_firmware
Node
sicklms511Match-
AND
sicklms511_firmware
Node
sicklms500Match-
AND
sicklms500_firmware

CNA Affected

[
  {
    "defaultStatus": "affected",
    "product": "LMS5xx",
    "vendor": "SICK AG",
    "versions": [
      {
        "status": "affected",
        "version": "all firmware versions"
      }
    ]
  }
]

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.3%

Related for CVE-2023-31412