Lucene search

K
vulnrichmentSICK AGVULNRICHMENT:CVE-2023-43697
HistoryOct 09, 2023 - 12:03 p.m.

CVE-2023-43697

2023-10-0912:03:27
CWE-471
SICK AG
github.com
cve-2023-43697
rdt400
sick apu
modification of assumed-immutable data
remote attacker
file paths
http requests

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

AI Score

7.1

Confidence

Low

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial

Modification of Assumed-Immutable Data (MAID) in RDT400 in SICK APU allows an
unprivileged remote attacker to make the site unable to load necessary strings via changing file paths
using HTTP requests.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:sick_ag:apu0200:*:*:*:*:*:*:*:*"
    ],
    "vendor": "sick_ag",
    "product": "apu0200",
    "versions": [
      {
        "status": "affected",
        "version": "rdt400"
      }
    ],
    "defaultStatus": "affected"
  }
]

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

AI Score

7.1

Confidence

Low

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial

Related for VULNRICHMENT:CVE-2023-43697