CVE-2024-10771: Sick INSPECTOR61X Firmware
High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.
Due to missing input validation during one step of the firmware update process, the product is vulnerable to remote code execution. With network access and the user level ”Service”, an attacker can execute arbitrary system commands in the root user’s contexts.
Affected products
- Sick INSPECTOR61X Firmware: before 5.0.0 (fixed in 5.0.0)
- Sick INSPECTOR62X Firmware: before 5.0.0 (fixed in 5.0.0)
- Sick TIM3XX: before 5.10.0 (fixed in 5.10.0)
- Sick AG Sick INSPECTORP61X: before 5.0.0 (fixed in 5.0.0)
- Sick AG Sick INSPECTORP62X: before 5.0.0 (fixed in 5.0.0)
- Sick AG Tdc-x401gl: any version
- Sick AG TIM3XX: before 5.10.0 (fixed in 5.10.0)
Published 2024-12-06. Last modified 2026-06-17.