// For flags

CVE-2022-27582

 

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Password recovery vulnerability in SICK SIM4000 (PPC) Partnumber 1078787 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an increase in their privileges on the system and thereby affecting the confidentiality integrity and availability of the system. An attacker can expect repeatable success by exploiting the vulnerability. The firmware versions <=1.10.1 allow to optionally disable device configuration over the network interfaces. Please make sure that you apply general security practices when operating the SIM4000. A fix is planned but not yet scheduled.

Vulnerabilidad de recuperación de contraseña en SICK SIM4000 (PPC) Partnumber 1078787, permite a un atacante remoto sin privilegios obtener acceso al nivel de usuario definido como RecoverableUserLevel invocando el método del mecanismo de recuperación de contraseña. Esto conduce a un aumento de sus privilegios en el sistema y, por lo tanto, afecta la integridad de la confidencialidad y la disponibilidad del sistema. Un atacante puede esperar un éxito repetible si explota la vulnerabilidad. Las versiones de firmware &lt;=1.10.1 permiten opcionalmente desactivar la configuración del dispositivo a través de las interfaces de red. Asegúrese de aplicar prácticas de seguridad generales al operar el SIM4000. Se planea una solución, pero aún no está programada.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-03-21 CVE Reserved
  • 2022-11-01 CVE Published
  • 2024-08-03 CVE Updated
  • 2024-12-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-306: Missing Authentication for Critical Function
CAPEC
References (1)
URL Tag Source
URL Date SRC
URL Date SRC
URL Date SRC
https://sick.com/psirt 2022-12-16
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sick
Search vendor "Sick"
Sim2000 Firmware
Search vendor "Sick" for product "Sim2000 Firmware"
< 1.2.0
Search vendor "Sick" for product "Sim2000 Firmware" and version " < 1.2.0"
-
Affected
in Sick
Search vendor "Sick"
Sim2000
Search vendor "Sick" for product "Sim2000"
--
Safe
Sick
Search vendor "Sick"
Sim2000st Firmware
Search vendor "Sick" for product "Sim2000st Firmware"
< 1.2.0
Search vendor "Sick" for product "Sim2000st Firmware" and version " < 1.2.0"
-
Affected
in Sick
Search vendor "Sick"
Sim2000st
Search vendor "Sick" for product "Sim2000st"
--
Safe
Sick
Search vendor "Sick"
Sim2500 Firmware
Search vendor "Sick" for product "Sim2500 Firmware"
< 1.2.0
Search vendor "Sick" for product "Sim2500 Firmware" and version " < 1.2.0"
-
Affected
in Sick
Search vendor "Sick"
Sim2500
Search vendor "Sick" for product "Sim2500"
--
Safe
Sick
Search vendor "Sick"
Sim1012 Firmware
Search vendor "Sick" for product "Sim1012 Firmware"
< 2.2.0
Search vendor "Sick" for product "Sim1012 Firmware" and version " < 2.2.0"
-
Affected
in Sick
Search vendor "Sick"
Sim1012
Search vendor "Sick" for product "Sim1012"
--
Safe
Sick
Search vendor "Sick"
Sim1004 Firmware
Search vendor "Sick" for product "Sim1004 Firmware"
< 2.0.0
Search vendor "Sick" for product "Sim1004 Firmware" and version " < 2.0.0"
-
Affected
in Sick
Search vendor "Sick"
Sim1004
Search vendor "Sick" for product "Sim1004"
--
Safe
Sick
Search vendor "Sick"
Sim1000 Fx Firmware
Search vendor "Sick" for product "Sim1000 Fx Firmware"
< 1.6.0
Search vendor "Sick" for product "Sim1000 Fx Firmware" and version " < 1.6.0"
-
Affected
in Sick
Search vendor "Sick"
Sim1000 Fx
Search vendor "Sick" for product "Sim1000 Fx"
--
Safe
Sick
Search vendor "Sick"
Sim4000 Firmware
Search vendor "Sick" for product "Sim4000 Firmware"
*-
Affected
in Sick
Search vendor "Sick"
Sim4000
Search vendor "Sick" for product "Sim4000"
--
Safe