The vendor explicitly identifies these products as affected by this CVE.
- SICK MSC800 with Firmware <4.0
- Summary
- The MSC800 uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure settings and /or disrupt the functionality of the device.
- Remediation
- SICK has released a firmware update for MSC800 and recommends updating to the new version V4.0. The update allows customers to change the default customer passwords and to optionally disable device configuration over desired networks interfaces, especially in critical infrastructures. The patch and installation procedure for the firmware update is available from the responsible SICK customer contact person. Until the firmware update is installed, general security practices should be utilized. In case the referenced patches cannot be applied, the following general security practices could mitigate the associated risk.
