CVE-2024-10772CWE-649
SICK InspectorP61x and SICK InspectorP62x are vulnerable for firmware modification
High · published December 6, 2024
What it is
Since the firmware update is not validated, an attacker can install modified firmware on the
device. This has a high impact on the availabilty, integrity and confidentiality up to the complete compromise of the device.
The record
Technical detail
- CVSS v3.1
- 8.8 · HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- CVSS v4.0
- Not supplied
- EPSS
- 0.00334 · 26.2th percentile
- Weakness
- CWE-649 · Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking
- Published
- 2024-12-06T12:28Z
EPSS history
Timeline