CVE-2023-23450: Sick Ftmg-ESD15AXX Firmware
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to use a password hash instead of an actual password to login to a valid user account via the REST interface.
Affected products
- Sick Ftmg-ESD15AXX Firmware: before 2.0 (fixed in 2.0)
- Sick Ftmg-ESD20AXX Firmware: before 2.0 (fixed in 2.0)
- Sick Ftmg-ESD25AXX Firmware: before 2.0 (fixed in 2.0)
- Sick Ftmg-ESN40SXX Firmware: before 2.0 (fixed in 2.0)
- Sick Ftmg-ESN50SXX Firmware: before 2.0 (fixed in 2.0)
- Sick Ftmg-ESR40SXX Firmware: before 2.0 (fixed in 2.0)
- Sick Ftmg-ESR50SXX Firmware: before 2.0 (fixed in 2.0)
Published 2023-05-15. Last modified 2026-06-17.