← Back to home
ICSA-19-178-04  ·  Published 2019-06-27  ·  View on CISA ICS-CERT ↗

SICK MSC800

CVSS 9.8 CRITICAL

Risk Summary

Successful exploitation of this vulnerability could allow a low-skilled remote attacker to reconfigure settings and/or disrupt the functionality of the device.

CVEs (1)

Remediations

  • SICK recommends affected users upgrade to the latest firmware version (v4.0).
  • The patch and installation procedure for the firmware update is available from the responsible SICK representative. Until the firmware update is installed, general security practices should be utilized.
  • In case the referenced patches cannot be applied, the following general security practices could mitigate the associated risk.
  • For more information SICK has released a security notification that can be found at: https://www.sick.com/de/en/service-and-support/the-sick-product-security-incident-response-team-sick-psirt/w/psirt/#advisories

Affected Vendors

SICK

Affected Products (1)

SICK · MSC800 < 4.0

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more