// For flags

CVE-2021-32496

 

Severity Score

5.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

SICK Visionary-S CX up version 5.21.2.29154R are vulnerable to an Inadequate Encryption Strength vulnerability concerning the internal SSH interface solely used by SICK for recovering returned devices. The use of weak ciphers make it easier for an attacker to break the security that protects information transmitted from the client to the SSH server, assuming the attacker has access to the network on which the device is connected. This can increase the risk that encryption will be compromised, leading to the exposure of sensitive user information and man-in-the-middle attacks.

SICK Visionary-S CX hasta la versión 5.21.2.29154R, son susceptibles a una vulnerabilidad de Fuerza de Encriptación Inadecuada relativa a la interfaz interna SSH utilizada únicamente por SICK para la recuperación de dispositivos devueltos. El uso de cifrados débiles facilita a un atacante rompa la seguridad que protege la información transmitida desde el cliente al servidor SSH, asumiendo que el atacante tenga acceso a la red en la que está conectado el dispositivo. Esto puede aumentar el riesgo de que la encriptación se vea comprometida, conllevando a la exposición de información confidencial del usuario y ataques de tipo man-in-the-middle

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-05-10 CVE Reserved
  • 2021-06-28 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-326: Inadequate Encryption Strength
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sick
Search vendor "Sick"
Visionary-s Cx Firmware
Search vendor "Sick" for product "Visionary-s Cx Firmware"
< 5.21.2.29154r
Search vendor "Sick" for product "Visionary-s Cx Firmware" and version " < 5.21.2.29154r"
-
Affected
in Sick
Search vendor "Sick"
Visionary-s Cx
Search vendor "Sick" for product "Visionary-s Cx"
--
Safe