<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_sick</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 08:50:48 +0000</lastBuildDate>
    <item>
      <title>sca-2026-0011 — Vulnerabilities in Wibu Systems CodeMeter Runtime Affect Multiple SICK Products</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2026-0011</link>
      <description>&lt;p&gt;cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary system path. Because CodeMeter Runtime runs with System privileges, this could allow arbitrary files to be deleted with System privileges and potentially enable local privilege escalation. If CodeMeter Runtime is configured as a server, the configuration command handler does not enforce network-origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover. The logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and remotely when combined with CVE‑2026‑81573 by setting General.ProxyServer and then triggering this vulnerability. If configured as a server, CodeMeter Runtime accepts requests with opcode 0x5e, wh…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary system path. Because CodeMeter Runtime runs with System privileges, this could allow arbitrary files to be deleted with System privileges and potentially enable local privilege escalation. If CodeMeter Runtime is configured as a server, the configuration command handler does not enforce network-origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover. The logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and remotely when combined with CVE‑2026‑81573 by setting General.ProxyServer and then triggering this vulnerability. If configured as a server, CodeMeter Runtime accepts requests with opcode 0x5e, wh…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2026-0011</guid>
      <pubDate>Fri, 04 Sep 2026 13:00:00 +0000</pubDate>
    </item>
    <item>
      <title>sca-2026-0013 — Vulnerabilities Affecting SICK CorivaEngine</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2026-0013</link>
      <description>&lt;p&gt;Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP request smuggling / protocol-confusion attacks. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final. Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque&amp;lt;CharSequence&amp;gt;` named `acceptEncodingQueue` that accumulates attacker-controlled data without any size limit. The queue is filled on the I/O thread for every inbound HTTP request and drained only when the application later writes a non-1xx response. This creates a resource exhaustion vulnerability when an attacker exploits HTTP/1.1 pipelining to flood the connection with requests faster than the application produces responses. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final. Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers. Affected versions: Spring Cloud Gatewa…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP request smuggling / protocol-confusion attacks. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final. Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque&amp;lt;CharSequence&amp;gt;` named `acceptEncodingQueue` that accumulates attacker-controlled data without any size limit. The queue is filled on the I/O thread for every inbound HTTP request and drained only when the application later writes a non-1xx response. This creates a resource exhaustion vulnerability when an attacker exploits HTTP/1.1 pipelining to flood the connection with requests faster than the application produces responses. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final. Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers. Affected versions: Spring Cloud Gatewa…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2026-0013</guid>
      <pubDate>Fri, 11 Sep 2026 16:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SCA-2026-0012 — Vulnerability Affecting Sentio Creator Extension 'Device Manager'</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2026-0012</link>
      <description>&lt;p&gt;An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of attacker-controlled code. User interaction is required.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of attacker-controlled code. User interaction is required.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2026-0012</guid>
      <pubDate>Fri, 11 Sep 2026 15:53:00 +0000</pubDate>
    </item>
    <item>
      <title>sca-2026-0010 — AppEngine vulnerability affects SICK ICR890-4 and SICK InspectorP6xx devices</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2026-0010</link>
      <description>&lt;p&gt;A vulnerability has been identified in the SOPAS FileSystemAccess method that allows unintended remote access to internal virtual filesystem paths. Due to insufficient access restrictions, an attacker with network access can query and modify internal storage locations, configuration files, and system-related application directories. This exposure may lead to the Denial of Service, unauthorized change of device configuration or disclosure of sensitive system information that could facilitate further attacks or compromise of the device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been identified in the SOPAS FileSystemAccess method that allows unintended remote access to internal virtual filesystem paths. Due to insufficient access restrictions, an attacker with network access can query and modify internal storage locations, configuration files, and system-related application directories. This exposure may lead to the Denial of Service, unauthorized change of device configuration or disclosure of sensitive system information that could facilitate further attacks or compromise of the device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2026-0010</guid>
      <pubDate>Mon, 24 Aug 2026 13:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SCA-2026-0009 — Vulnerability in several Endress+Hauser products</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2026-0009</link>
      <description>&lt;p&gt;A vulnerability was discovered in several Endress+Hauser products that can be accessed via ethernet.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was discovered in several Endress+Hauser products that can be accessed via ethernet.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2026-0009</guid>
      <pubDate>Thu, 16 Jul 2026 13:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SCA-2026-0008 — Vulnerability Affecting SICK Sentio Creator Extension “Software Deployment Manager”</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2026-0008</link>
      <description>&lt;p&gt;Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2026-0008</guid>
      <pubDate>Fri, 10 Jul 2026 13:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SCA-2025-0010 — Multiple vulnerabilities in SICK Enterprise Analytics and SICK Logistic Analytics Products</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2025-0010</link>
      <description>&lt;p&gt;The credentials of the users stored in the system&amp;#39;s local database can be used for the log in, making it possible for an attacker to gain unauthorized access. This could potentially affect the confidentiality of the application. JavaScript can be run inside the address bar via the dashboard &amp;#34;Open in new Tab&amp;#34; button, making the application vulnerable to session hijacking. The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possible for an attacker to guess user credentials. A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration settings of the product. When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker thus receives information about the technology used and the structure of the application. It&amp;#39;s possible to brute force folders and files, which can be used by an attacker to steal sensitive information. A remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, making the application vulnerable for gathering sensitive information. In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The credentials of the users stored in the system&amp;#39;s local database can be used for the log in, making it possible for an attacker to gain unauthorized access. This could potentially affect the confidentiality of the application. JavaScript can be run inside the address bar via the dashboard &amp;#34;Open in new Tab&amp;#34; button, making the application vulnerable to session hijacking. The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possible for an attacker to guess user credentials. A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration settings of the product. When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker thus receives information about the technology used and the structure of the application. It&amp;#39;s possible to brute force folders and files, which can be used by an attacker to steal sensitive information. A remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, making the application vulnerable for gathering sensitive information. In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2025-0010</guid>
      <pubDate>Thu, 02 Oct 2025 13:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SCA-2026-0007 — Sudo vulnerability affects Endress+Hauser MCS200HW</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2026-0007</link>
      <description>&lt;p&gt;The display unit of the Endress+Hauser MCS200HW is affected by a sudo chroot vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The display unit of the Endress+Hauser MCS200HW is affected by a sudo chroot vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2026-0007</guid>
      <pubDate>Tue, 21 Apr 2026 13:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SCA-2025-0003 — FreeRTOS Vulnerabilities have no impact on SICK Products</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2025-0003</link>
      <description>&lt;p&gt;FreeRTOS is a real-time operating system for microcontrollers. FreeRTOS Kernel versions through 10.6.1 do not sufficiently protect against local privilege escalation via Return Oriented Programming techniques should a vulnerability exist that allows code injection and execution. These issues affect ARMv7-M MPU ports, and ARMv8-M ports with Memory Protected Unit (MPU) support enabled (i.e. `configENABLE_MPU` set to 1). These issues are fixed in version 10.6.2 with a new MPU wrapper. Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component allow remote attackers to execute arbitrary code or leak information because of a Buffer Overflow during parsing of DNS\LLMNR packets in prvParseDNSReply. FreeRTOS versions 10.2.0 through 10.4.5 do not prevent non-kernel code from calling the xPortRaisePrivilege internal function to raise privilege. FreeRTOS versions through 10.4.6 do not prevent a third party that has already independently gained the ability to execute injected code to achieve further privilege escalation by branching directly inside a FreeRTOS MPU API wrapper function with a manually crafted stack frame. These issues affect ARMv7-M MPU ports, and ARMv8-M ports with MPU support enabled (i.e. configENABLE_MPU set to 1). These are fixed in V10.5.0 and in V10.4.3-LTS Patch 3. The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;FreeRTOS is a real-time operating system for microcontrollers. FreeRTOS Kernel versions through 10.6.1 do not sufficiently protect against local privilege escalation via Return Oriented Programming techniques should a vulnerability exist that allows code injection and execution. These issues affect ARMv7-M MPU ports, and ARMv8-M ports with Memory Protected Unit (MPU) support enabled (i.e. `configENABLE_MPU` set to 1). These issues are fixed in version 10.6.2 with a new MPU wrapper. Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component allow remote attackers to execute arbitrary code or leak information because of a Buffer Overflow during parsing of DNS\LLMNR packets in prvParseDNSReply. FreeRTOS versions 10.2.0 through 10.4.5 do not prevent non-kernel code from calling the xPortRaisePrivilege internal function to raise privilege. FreeRTOS versions through 10.4.6 do not prevent a third party that has already independently gained the ability to execute injected code to achieve further privilege escalation by branching directly inside a FreeRTOS MPU API wrapper function with a manually crafted stack frame. These issues affect ARMv7-M MPU ports, and ARMv8-M ports with MPU support enabled (i.e. configENABLE_MPU set to 1). These are fixed in V10.5.0 and in V10.4.3-LTS Patch 3. The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2025-0003</guid>
      <pubDate>Fri, 28 Feb 2025 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>SCA-2026-0006 — Vulnerabilities affecting SICK Lector85x and SICK Lector83x</title>
      <link>https://cve.radiocsirt.org/vuln/sca-2026-0006</link>
      <description>&lt;p&gt;An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain directories intended for internal testing were not covered by the whitelist and are accessible without authentication. An unauthenticated attacker could place a manipulated parameter file that becomes active after a reboot, allowing modification of critical device settings, including network configuration and application parameters. An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain directories intended for internal testing were not covered by the whitelist and are accessible without authentication. An unauthenticated attacker could place a manipulated parameter file that becomes active after a reboot, allowing modification of critical device settings, including network configuration and application parameters. An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sca-2026-0006</guid>
      <pubDate>Fri, 06 Mar 2026 14:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
