The vendor explicitly identifies these products as affected by this CVE.
- SICK RFU610-10600 with Firmware <2.25
- SICK RFU610-10601 with Firmware <2.25
- SICK RFU610-10603 with Firmware <2.25
- SICK RFU610-10604 with Firmware <2.25
- SICK RFU610-10605 with Firmware <2.25
- SICK RFU610-10607 with Firmware <2.25
- SICK RFU610-10609 with Firmware <2.25
- SICK RFU610-10610 with Firmware <2.25
- SICK RFU610-10613 with Firmware <2.25
- SICK RFU610-10614 with Firmware <2.25
- SICK RFU610-10618 with Firmware <2.25
- SICK RFU610-10700 with Firmware <2.25
- Summary
- Use of a Broken or Risky Cryptographic Algorithm in SICK RFU61x firmware version < v2.25 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encryption via the SSH interface.
- Remediation
- The patch and installation procedure for the firmware update is available from the responsible SICK customer contact person.
