Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

SICK AG

First CVE: Jul 1, 2019Active for: 7 yearsTotal CVEs: 123
32.7
VTI Score
Medium

SICK AG manufactures a broad portfolio of sensor systems, analytics platforms, and diagnostic software spanning industrial automation, logistics, and baggage handling—products deeply embedded in manufacturing and supply-chain infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and concentrate in authentication and access-control weaknesses across its package analytics, logistics diagnostic platforms, and embedded firmware components. The recurring weakness classes—missing authentication for critical functions, improper access control, and reliance on broken cryptographic algorithms—reflect the legacy design and networked-system demands of industrial sensing and monitoring equipment. Defenders should prioritize inventory and network segmentation for SICK systems exposed to untrusted networks and treat authentication and cryptographic weaknesses in this domain as high-risk. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
123
Total CVEs
More Total CVEs than 99% of tracked vendors
0.1
Avg CVEs / Product / Year
Bottom 1%
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by SICK AG over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 1, 2019
7 years ago
Most Recent CVE
Feb 27, 2026
147 days ago

Self-Reporting Analysis

Of all the CVEs published by SICK AG as a CNA, 75.6% affect products that SICK AG develops as a vendor.

75.6%
24.4%
Self-reported: 121 (75.6%)
Third-party: 39 (24.4%)

Of all the CVEs published that affect products developed by SICK AG, 98.4% are self-published by SICK AG as a CNA.

98.4%
Self-published: 121 (98.4%)
Other CNAs: 2 (1.6%)

Products(291 total)

Top CVEs

Signals from CVEs in this vendor scope (123 CVEs).

123 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-22907CRITICAL
An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.
Jan 15, 20269.133NONO
CVE-2026-22910CRITICAL
The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the
Jan 15, 20269.132NONO
CVE-2026-22909CRITICAL
Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potentially disrupting system operations
Jan 15, 20269.132NONO
CVE-2022-27582CRITICAL
Password recovery vulnerability in SICK SIM4000 (PPC) Partnumber 1078787 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by i
Nov 1, 20229.832NONO
CVE-2019-10979CRITICAL
SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password.
Jul 1, 20199.831NONO
CVE-2025-59461CRITICAL
A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services.
Oct 27, 20259.830NONO
CVE-2025-58587CRITICAL
The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possible for an attacker to guess use
Oct 6, 20259.830NONO
CVE-2023-23450CRITICAL
Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an un
May 15, 20239.830NONO
CVE-2023-23453CRITICAL
Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution
Feb 20, 20239.830NONO
CVE-2022-27586CRITICAL
Password recovery vulnerability in SICK SIM1004 Partnumber 1098148 with firmware version <2.0.0 allows an unprivileged remote attacker to gain access to the userlevel defined as Re
Nov 1, 20229.830NONO
View all 123 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products123 CVEs
33%
45%
22%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (4.1%)
Network117 (95.1%)
Unknown0 (0.0%)
Physical1 (0.8%)
Adjacent Network0 (0.0%)
Attack Complexity
Low120 (97.6%)
High3 (2.4%)
Unknown0 (0.0%)
User Interaction
None104 (84.6%)
Unknown0 (0.0%)
Required19 (15.4%)
Privileges Required
Low15 (12.2%)
High2 (1.6%)
None106 (86.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (123 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by SICK AG.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by SICK AG — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For SICK AG's Products

View all 3 CNAs →

Top CWEs