CVE-2023-23449
Published: May 15, 2023
Modified: Jun 1, 2026
CVSS v3.1
5.3
Description
Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames by analyzing challenge responses from the server via the REST interface.
| Vendor | Product | Versions |
|---|---|---|
SICK AG | SICK FTMG-ESD15AXX AIR FLOW SENSOR | affected all firmware versions |
SICK AG | SICK FTMG-ESD20AXX AIR FLOW SENSOR | affected all firmware versions |
SICK AG | SICK FTMG-ESD25AXX AIR FLOW SENSOR | affected all firmware versions |
SICK AG | SICK FTMG-ESN40SXX AIR FLOW SENSOR | affected all firmware versions |
SICK AG | SICK FTMG-ESN50SXX AIR FLOW SENSOR | affected all firmware versions |
SICK AG | SICK FTMG-ESR40SXX AIR FLOW SENSOR | affected all firmware versions |
SICK AG | SICK FTMG-ESR50SXX AIR FLOW SENSOR | affected all firmware versions |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now