V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2023-23448
CVE
Medium

Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116…

CVSS
5.3
Medium
EPSS
0.01
p51
Published
2023-01-01
Updated
2023-01-01
Description

Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis of source code.

Tags · CWE
Pre-auth
CWE-540
Affected products
Ftmg-esd15axx_firmwareFtmg-esd20axx_firmwareFtmg-esd25axx_firmwareFtmg-esn40sxx_firmwareFtmg-esn50sxx_firmwareFtmg-esr40sxx_firmwareFtmg-esr50sxx_firmware
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.008 · p51
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
ftmg-esd15axx_firmware*Tracked
ftmg-esd20axx_firmware*Tracked
ftmg-esd25axx_firmware*Tracked
ftmg-esn40sxx_firmware*Tracked
ftmg-esn50sxx_firmware*Tracked
ftmg-esr40sxx_firmware*Tracked
ftmg-esr50sxx_firmware*Tracked
Source databases
CVE