CVE-2023-43697

Modification of Assumed-Immutable Data (MAID) in RDT400 in SICK APU allows an unprivileged remote attacker to make the site unable to load necessary strings via changing file paths using HTTP requests.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sick:apu0200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sick:apu0200:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:24

Type Values Removed Values Added
References () https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.json - Vendor Advisory () https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.json - Vendor Advisory
References () https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.pdf - Vendor Advisory () https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.pdf - Vendor Advisory
References () https://sick.com/psirt - Product () https://sick.com/psirt - Product

11 Oct 2023, 18:49

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE NVD-CWE-Other
First Time Sick apu0200 Firmware
Sick
Sick apu0200
CPE cpe:2.3:h:sick:apu0200:-:*:*:*:*:*:*:*
cpe:2.3:o:sick:apu0200_firmware:*:*:*:*:*:*:*:*
References (MISC) https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.pdf - (MISC) https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.pdf - Vendor Advisory
References (MISC) https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.json - (MISC) https://sick.com/.well-known/csaf/white/2023/sca-2023-0010.json - Vendor Advisory
References (MISC) https://sick.com/psirt - (MISC) https://sick.com/psirt - Product

09 Oct 2023, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-09 13:15

Updated : 2024-11-21 08:24


NVD link : CVE-2023-43697

Mitre link : CVE-2023-43697

CVE.ORG link : CVE-2023-43697


JSON object : View

Products Affected

sick

  • apu0200_firmware
  • apu0200
CWE
CWE-471

Modification of Assumed-Immutable Data (MAID)

NVD-CWE-Other