CVE-2023-35699: Sick ICR890-4 Firmware

Medium severity, CVSS 4.6. EPSS: 0.2% chance of exploitation in the next 30 days.

Cleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device to disclose sensitive information by accessing a SD card.

Affected products

  • Sick ICR890-4 Firmware: before 2.5.0 (fixed in 2.5.0)

Published 2023-07-10. Last modified 2026-06-17.