The LMS5xx uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure settings and /or disrupt the functionality of the device.
Solution:
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://sick.com/psirt | vendor advisory issue tracking |
https://sick.com/.well-known/csaf/white/2023/sca-2023-0007.pdf | vendor advisory |
https://sick.com/.well-known/csaf/white/2023/sca-2023-0007.json | vendor advisory |