Lucene search

K
vulnrichmentSICK AGVULNRICHMENT:CVE-2023-43699
HistoryOct 09, 2023 - 11:59 a.m.

CVE-2023-43699

2023-10-0911:59:19
CWE-307
SICK AG
github.com
cve-2023-43699
remote attacker
password guessing

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.4

Confidence

Low

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial

Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU
allows an unprivileged remote attacker to guess the password via trial-and-error as the login attempts
are not limited.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:sick_ag:apu0200:*:*:*:*:*:*:*:*"
    ],
    "vendor": "sick_ag",
    "product": "apu0200",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.4

Confidence

Low

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial

Related for VULNRICHMENT:CVE-2023-43699