VendorsSICKapu0200any version
Vulnerabilities

SICK APU0200 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2023-43696
Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous access to the FTP server.
Published 2023-10-09 · Modified
9.8EPSS 0.006
CVE-2023-43700
Missing Authorization in RDT400 in SICK APU allows an unprivileged remote attacker to modify data via HTTP requests that no not require authentication.
Published 2023-10-09 · Modified
7.7EPSS 0.006
CVE-2023-43699
Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU allows an unprivileged remote attacker to guess the password via trial-and-error as the login attempts are not limited.
Published 2023-10-09 · Modified
7.5EPSS 0.007
CVE-2023-43698
Improper Neutralization of Input During Web Page Generation (’Cross-site Scripting’) in RDT400 in SICK APU allows an unprivileged remote attacker to run arbitrary code in the clients browser via injecting code into the website.
Published 2023-10-09 · Modified
7.1EPSS 0.005
CVE-2023-43697
Modification of Assumed-Immutable Data (MAID) in RDT400 in SICK APU allows an unprivileged remote attacker to make the site unable to load necessary strings via changing file paths using HTTP requests.
Published 2023-10-09 · Modified
6.5EPSS 0.006
CVE-2023-5100
Cleartext Transmission of Sensitive Information in RDT400 in SICK APU allows an unprivileged remote attacker to retrieve potentially sensitive information via intercepting network traffic that is not encrypted.
Published 2023-10-09 · Modified
6.5EPSS 0.004
CVE-2023-5101
Files or Directories Accessible to External Parties in RDT400 in SICK APU allows an unprivileged remote attacker to download various files from the server via HTTP requests.
Published 2023-10-09 · Modified
5.3EPSS 0.006
CVE-2023-5102
Insufficient Control Flow Management in RDT400 in SICK APU allows an unprivileged remote attacker to potentially enable hidden functionality via HTTP requests.
Published 2023-10-09 · Modified
5.3EPSS 0.006
CVE-2023-5103
Improper Restriction of Rendered UI Layers or Frames in RDT400 in SICK APU allows an unprivileged remote attacker to potentially reveal sensitive information via tricking a user into clicking on an actionable item using an iframe.
Published 2023-10-09 · Modified
4.3EPSS 0.005