CVE-2024-10774: SICK InspectorP61x and SICK InspectorP62x have unauthenticated CROWN APIs

7.3 CVSS

Description

Unauthenticated CROWN APIs allow access to critical functions. This leads to the accessibility of large parts of the web application without authentication.

Classification

CVE ID: CVE-2024-10774

CVSS Base Severity: HIGH

CVSS Base Score: 7.3

Affected Products

Vendor: SICK AG

Product: SICK InspectorP61x

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 14.88% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://sick.com/psirt
https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF
https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
https://www.first.org/cvss/calculator/3.1
https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.pdf
https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.json

Timeline