CVE-2023-4419: Sick LMS500 Firmware

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

The LMS5xx uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure settings and /or disrupt the functionality of the device.

Affected products

  • Sick LMS500 Firmware: any version
  • Sick LMS511 Firmware: any version
  • Sick LMS531 Firmware: any version

Published 2023-08-24. Last modified 2026-06-17.