CVE-2023-23450

Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to use a password hash instead of an actual password to login to a valid user account via the REST interface.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sick:ftmg-esd20axx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sick:ftmg-esd20axx:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:sick:ftmg-esd25axx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sick:ftmg-esd25axx:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:sick:ftmg-esn40sxx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sick:ftmg-esn40sxx:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:sick:ftmg-esn50sxx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sick:ftmg-esn50sxx:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:sick:ftmg-esr50sxx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sick:ftmg-esr50sxx:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:sick:ftmg-esr40sxx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sick:ftmg-esr40sxx:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:sick:ftmg-esd15axx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sick:ftmg-esd15axx:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-05-15 11:15

Updated : 2023-05-30 14:11


NVD link : CVE-2023-23450

Mitre link : CVE-2023-23450

CVE.ORG link : CVE-2023-23450


JSON object : View

Products Affected

sick

  • ftmg-esn40sxx
  • ftmg-esr50sxx_firmware
  • ftmg-esn40sxx_firmware
  • ftmg-esd25axx_firmware
  • ftmg-esd15axx
  • ftmg-esr40sxx_firmware
  • ftmg-esr50sxx
  • ftmg-esd20axx
  • ftmg-esn50sxx_firmware
  • ftmg-esn50sxx
  • ftmg-esr40sxx
  • ftmg-esd25axx
  • ftmg-esd15axx_firmware
  • ftmg-esd20axx_firmware
CWE
CWE-287

Improper Authentication

CWE-836

Use of Password Hash Instead of Password for Authentication