The vendor explicitly identifies these products as affected by this CVE.
- SICK CLV62x with Firmware <=6.10
- SICK CLV63x with Firmware <=6.10
- SICK CLV64x with Firmware <=6.10
- SICK CLV65x with Firmware <=6.10
- SICK LMS10x with Firmware <2.0
- SICK LMS11x with Firmware <2.0
- SICK LMS15x with Firmware <2.0
- SICK LMS12x with Firmware <2.1
- SICK LMS13x with Firmware <2.1
- SICK LMS14x with Firmware <2.1
- SICK LMS5xx all Firmware versions
- SICK LMS53x all Firmware versions
- Summary
- Improper handling of exceptional conditions in the platform mechanism AutoIP can lead to a reboot of the device, if parsing malformed network packets. This can lead to a temporary impact of the availability of the device. The AutoIP mechanism is used by the SOPAS Engineering Tool (SOPAS-ET), e.g. to detect SICK devices in the network and change their IP configuration. This is intended to simplify the initial setup and the maintenance of the devices. The devices listen on port 30718 for UDP broadcasts. SICK has released a new firmware version for the MSC800, Bulkscan LMS111, Bulkscan LMS511 and other LMS1xx devices.
- Remediation
- Update to version V1.04 SICK removed the AutoIP weakness with the same available fix for the MSC800. The update can only be implemented by a SICK service technician, either by remote access or on site. To obtain the update, please contact your local service technician.
