A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings. The adversary may also reset the SIM and in the worst case upload a new firmware version to the device.
Solution:
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://sick.com/psirt | vendor advisory issue tracking |
https://sick.com/.well-known/csaf/white/2023/sca-2023-0008.pdf | mitigation vendor advisory |
https://sick.com/.well-known/csaf/white/2023/sca-2023-0008.json | vendor advisory |