Improper Restriction of Excessive Authentication Attempts in the SICK ICR890-4 could allow a remote attacker to brute-force user credentials.
Solution:
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Link | Tags |
---|---|
https://sick.com/psirt | product issue tracking |
https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.pdf | vendor advisory |
https://sick.com/.well-known/csaf/white/2023/sca-2023-0006.json | vendor advisory |