CVE-2023-3271

Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endpoints.

high 8.2 CVSS 3.1
Published: Jul 10, 2023
Modified: Jun 1, 2026
Vendor: Sick
Product: Icr890-4 Firmware

Description

Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing
unauthenticated endpoints.

References

Related CVEs