SICK AG manufactures a broad portfolio of sensor systems, analytics platforms, and diagnostic software spanning industrial automation, logistics, and baggage handling—products deeply embedded in manufacturing and supply-chain infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and concentrate in authentication and access-control weaknesses across its package analytics, logistics diagnostic platforms, and embedded firmware components. The recurring weakness classes—missing authentication for critical functions, improper access control, and reliance on broken cryptographic algorithms—reflect the legacy design and networked-system demands of industrial sensing and monitoring equipment. Defenders should prioritize inventory and network segmentation for SICK systems exposed to untrusted networks and treat authentication and cryptographic weaknesses in this domain as high-risk. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by SICK AG over time
Of all the CVEs published by SICK AG as a CNA, 75.6% affect products that SICK AG develops as a vendor.
Of all the CVEs published that affect products developed by SICK AG, 98.4% are self-published by SICK AG as a CNA.
Signals from CVEs in this vendor scope (123 CVEs).
123 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22907CRITICAL An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data. | Jan 15, 2026 | 9.1 | 33 | NO | NO |
CVE-2026-22910CRITICAL The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the | Jan 15, 2026 | 9.1 | 32 | NO | NO |
CVE-2026-22909CRITICAL Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potentially disrupting system operations | Jan 15, 2026 | 9.1 | 32 | NO | NO |
CVE-2022-27582CRITICAL Password recovery vulnerability in SICK SIM4000 (PPC) Partnumber 1078787 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by i | Nov 1, 2022 | 9.8 | 32 | NO | NO |
CVE-2019-10979CRITICAL SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password. | Jul 1, 2019 | 9.8 | 31 | NO | NO |
CVE-2025-59461CRITICAL A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services. | Oct 27, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-58587CRITICAL The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possible for an attacker to guess use | Oct 6, 2025 | 9.8 | 30 | NO | NO |
CVE-2023-23450CRITICAL Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR
FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526
allows an un | May 15, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-23453CRITICAL Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution | Feb 20, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-27586CRITICAL Password recovery vulnerability in SICK SIM1004 Partnumber 1098148 with firmware version <2.0.0 allows an unprivileged remote attacker to gain access to the userlevel defined as Re | Nov 1, 2022 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (123 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by SICK AG.
Media articles that mention a CVE ID that affects a product developed by SICK AG — matched by CVE ID, not by vendor name.