CVE-2023-23450
6.2 MEDIUMUse of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120...
Published: 2023-05-15 · Last updated: 2026-06-01
Severity and scoring
- CVSS
- 6.2 MEDIUM
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- CWE
- CWE-287, CWE-836
Affected products
| Vendor | Product |
|---|---|
| sick | ftmg-esd15axx_firmware, ftmg-esd20axx_firmware, ftmg-esd25axx_firmware |
Description
Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to use a password hash instead of an actual password to login to a valid user account via the REST interface.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2023-23450
- [Vendor advisory]https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.json
- [Vendor advisory]https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf
- [Vendor advisory]https://sick.com/psirt
- [Vendor advisory]https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.json
- [Vendor advisory]https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf
- [Vendor advisory]https://sick.com/psirt
Related CVEs
Same vendor
- CVE-2023-3273 — Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by c... (7.5 HIGH)
- CVE-2023-3272 — Cleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a remote attacker to gather sensitive information by int... (7.5 HIGH)
- CVE-2023-3271 — Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and do... (8.2 HIGH)
- CVE-2023-35699 — Cleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device to disclose sensit... (5.3 MEDIUM)
- CVE-2023-35698 — Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the FTP server from th... (5.3 MEDIUM)
Same CWE
- CVE-2026-48780 — Forem is open source software for building communities (8.2 HIGH)
- CVE-2026-48114 — Metacat is data repository software that helps researchers preserve, share, and discover data (9.8 CRITICAL)
- CVE-2026-12183 — Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerabili... (9.8 CRITICAL)
- CVE-2026-50623 — An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF (4.8 MEDIUM)
- CVE-2026-48611 — Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading t... (9.8 CRITICAL)