TROYANOSYVIRUS
Back to CVEs

CVE-2023-23453

CRITICAL
9.8

Description

Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.

CVE Details

CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published2/20/2023
Last Modified3/18/2025
Sourcenvd
Honeypot Sightings0

Affected Products

sick:fx0-gent00000sick:fx0-gent00000_firmwaresick:fx0-gent00010sick:fx0-gent00010_firmware

Weaknesses (CWE)

CWE-306CWE-306CWE-306

References

https://sick.com/psirt(psirt@sick.de)
https://sick.com/psirt(af854a3a-2127-422b-91ae-364da2661108)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.