CVE-2022-27586 is a critical password recovery vulnerability affecting SICK SIM1004 Partnumber 1098148 devices with firmware versions prior to 2.0.0. An unprivileged remote attacker can exploit this flaw to invoke the password recovery mechanism, gaining elevated privileges up to the "RecoverableUserLevel." This significantly impacts the confidentiality, integrity, and availability of the affected system. The vulnerability carries a CVSS score of 9.8 (Critical), indicating it is easily exploitable over the network with low attack complexity and no user interaction required, leading to complete compromise. While the EPSS score is low, suggesting a lower probability of exploitation compared to most CVEs, the FAUCET Risk Score of 79/100 highlights its significant potential impact. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal. The recommended mitigation is to immediately update the firmware to version 2.0.0 or higher.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.0CPE matchmatch criteria | cpe:2.3:o:sick:sim1004-0p0g311_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.