The vendor explicitly identifies these products as affected by this CVE.
- SICK RFU620-10100 with Firmware <2.21
- SICK RFU620-10101 with Firmware <2.21
- SICK RFU620-10102 with Firmware <2.21
- SICK RFU620-10103 with Firmware <2.21
- SICK RFU620-10104 with Firmware <2.21
- SICK RFU620-10105 with Firmware <2.21
- SICK RFU620-10107 with Firmware <2.21
- SICK RFU620-10108 with Firmware <2.21
- SICK RFU620-10111 with Firmware <2.21
- SICK RFU620-10114 with Firmware <2.21
- SICK RFU620-10118 with Firmware <2.21
- SICK RFU620-10400 with Firmware <2.21
- Summary
- Use of a Broken or Risky Cryptographic Algorithm in SICK RFU62x firmware version < 2.21 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encryption via the SSH interface.
- Remediation
- The patch and installation procedure for the firmware update is available from the responsible SICK customer contact person.
