CVE-2023-23444

Description

Missing Authentication for Critical Function in SICK Flexi Classic and Flexi Soft Gateways with Partnumbers 1042193, 1042964, 1044078, 1044072, 1044073, 1044074, 1099830, 1099832, 1127717, 1069070, 1112296, 1051432, 1102420, 1127487, 1121596, 1121597 allows an unauthenticated remote attacker to influence the availability of the device by changing the IP settings of the device via broadcasted UDP packets.

Remediation

Workaround:

  • Please make sure that you apply general security practices when operating the Flexi Classic and Flexi Soft Gateways like network segmentation. The following General Security Practices and Operating Guidelines could mitigate the associated security risk.

Category

7.5
CVSS
Severity: High
CVSS 3.1 •
EPSS 0.57%
Vendor Advisory sick.com Vendor Advisory sick.com Vendor Advisory sick.com
Affected: SICK AG UE410-EN3 FLEXI ETHERNET GATEW.
Affected: SICK AG UE410-EN1 FLEXI ETHERNET GATEW.
Affected: SICK AG UE410-EN4 FLEXI ETHERNET GATEW.
Affected: SICK AG FX0-GENT00000 FLEXISOFT EIP GATEW.
Affected: SICK AG FX0-GMOD00000 FLEXISOFT MOD GATEW.
Affected: SICK AG FX0-GPNT00000 FLEXISOFT PNET GATEW.
Affected: SICK AG FX0-GENT00030 FLEXISOFT EIP GATEW.V2
Affected: SICK AG FX0-GPNT00030 FLEXISOFT PNET GATEW.V2
Affected: SICK AG FX0-GMOD00010 FLEXISOFT MOD GW (C)
Affected: SICK AG FX3-GEPR00000 FLEXISOFT EFI-PRO GW
Affected: SICK AG FX3-GEPR00010 FLEXISOFT EFI-PRO GW
Affected: SICK AG FX0-GETC00000 FLEXISOFT ETC GW
Affected: SICK AG FX0-GETC00040 FLEXISOFT ETC GW
Affected: SICK AG FX0-GETC00010 FLEXISOFT ETC GW (C)
Affected: SICK AG FX0-GENT00010 FLEXISOFT EIP GW (C)
Affected: SICK AG FX0-GPNT00010 FLEXISOFT PNET GW (C)
Affected: SICK AG UE410-EN3 FLEXI ETHERNET GATEW. Firmware
Affected: SICK AG UE410-EN1 FLEXI ETHERNET GATEW. Firmware
Affected: SICK AG UE410-EN4 FLEXI ETHERNET GATEW. Firmware
Affected: SICK AG FX0-GENT00000 FLEXISOFT EIP GATEW. Firmware
Affected: SICK AG FX0-GMOD00000 FLEXISOFT MOD GATEW. Firmware
Affected: SICK AG FX0-GPNT00000 FLEXISOFT PNET GATEW. Firmware
Affected: SICK AG FX0-GENT00030 FLEXISOFT EIP GATEW.V2 Firmware
Affected: SICK AG FX0-GPNT00030 FLEXISOFT PNET GATEW.V2 Firmware
Affected: SICK AG FX0-GMOD00010 FLEXISOFT MOD GW (C) Firmware
Affected: SICK AG FX3-GEPR00000 FLEXISOFT EFI-PRO GW Firmware
Affected: SICK AG FX3-GEPR00010 FLEXISOFT EFI-PRO GW Firmware
Affected: SICK AG FX0-GETC00000 FLEXISOFT ETC GW Firmware
Affected: SICK AG FX0-GETC00040 FLEXISOFT ETC GW Firmware
Affected: SICK AG FX0-GETC00010 FLEXISOFT ETC GW (C) Firmware
Affected: SICK AG FX0-GENT00010 FLEXISOFT EIP GW (C) Firmware
Affected: SICK AG FX0-GPNT00010 FLEXISOFT PNET GW (C) Firmware
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2023-23444?
CVE-2023-23444 has been scored as a high severity vulnerability.
How to fix CVE-2023-23444?
As a workaround for remediating CVE-2023-23444: Please make sure that you apply general security practices when operating the Flexi Classic and Flexi Soft Gateways like network segmentation. The following General Security Practices and Operating Guidelines could mitigate the associated security risk.
Is CVE-2023-23444 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2023-23444 is being actively exploited. According to its EPSS score, there is a ~1% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2023-23444?
CVE-2023-23444 affects SICK AG UE410-EN3 FLEXI ETHERNET GATEW., SICK AG UE410-EN1 FLEXI ETHERNET GATEW., SICK AG UE410-EN4 FLEXI ETHERNET GATEW., SICK AG FX0-GENT00000 FLEXISOFT EIP GATEW., SICK AG FX0-GMOD00000 FLEXISOFT MOD GATEW., SICK AG FX0-GPNT00000 FLEXISOFT PNET GATEW., SICK AG FX0-GENT00030 FLEXISOFT EIP GATEW.V2, SICK AG FX0-GPNT00030 FLEXISOFT PNET GATEW.V2, SICK AG FX0-GMOD00010 FLEXISOFT MOD GW (C), SICK AG FX3-GEPR00000 FLEXISOFT EFI-PRO GW, SICK AG FX3-GEPR00010 FLEXISOFT EFI-PRO GW, SICK AG FX0-GETC00000 FLEXISOFT ETC GW, SICK AG FX0-GETC00040 FLEXISOFT ETC GW, SICK AG FX0-GETC00010 FLEXISOFT ETC GW (C), SICK AG FX0-GENT00010 FLEXISOFT EIP GW (C), SICK AG FX0-GPNT00010 FLEXISOFT PNET GW (C), SICK AG UE410-EN3 FLEXI ETHERNET GATEW. Firmware, SICK AG UE410-EN1 FLEXI ETHERNET GATEW. Firmware, SICK AG UE410-EN4 FLEXI ETHERNET GATEW. Firmware, SICK AG FX0-GENT00000 FLEXISOFT EIP GATEW. Firmware, SICK AG FX0-GMOD00000 FLEXISOFT MOD GATEW. Firmware, SICK AG FX0-GPNT00000 FLEXISOFT PNET GATEW. Firmware, SICK AG FX0-GENT00030 FLEXISOFT EIP GATEW.V2 Firmware, SICK AG FX0-GPNT00030 FLEXISOFT PNET GATEW.V2 Firmware, SICK AG FX0-GMOD00010 FLEXISOFT MOD GW (C) Firmware, SICK AG FX3-GEPR00000 FLEXISOFT EFI-PRO GW Firmware, SICK AG FX3-GEPR00010 FLEXISOFT EFI-PRO GW Firmware, SICK AG FX0-GETC00000 FLEXISOFT ETC GW Firmware, SICK AG FX0-GETC00040 FLEXISOFT ETC GW Firmware, SICK AG FX0-GETC00010 FLEXISOFT ETC GW (C) Firmware, SICK AG FX0-GENT00010 FLEXISOFT EIP GW (C) Firmware, SICK AG FX0-GPNT00010 FLEXISOFT PNET GW (C) Firmware.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.