CVE-2023-23451 describes a critical vulnerability in various SICK Flexi Classic and Flexi Soft Gateway models, where Telnet is enabled by default without a password. This flaw, rated 9.8 CVSS (CRITICAL), allows unauthenticated remote attackers to gain full control over affected devices due to the lack of authentication. While there is no evidence of active exploitation, public exploit code, or significant community discussion, the ease of exploitation and severe impact (complete compromise) make it a high-risk vulnerability. Organizations using the specified SICK gateways should immediately disable Telnet or implement strong authentication to mitigate this threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:sick:ue410-en3_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:sick:ue410-en1_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:sick:ue410-en3s04_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:sick:ue410-en4_firmware:*:*:*:*:*:*:*:* | ||
<= 2.11.0CPE matchmatch criteria | cpe:2.3:o:sick:fx0-gent00000_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Use of Telnet in the interface module SLC-0-GPNT00300
Apr 28, 2023Use of Telnet in the interface module SLC-0-GPNT00300
Apr 28, 2023Use of Telnet in the interface module SLC-0-GPNT00300
Apr 28, 2023Use of Telnet in the interface module SLC-0-GPNT00300
Apr 28, 2023