The vendor explicitly identifies these products as affected by this CVE.
- SICK RFU630-04100 with Firmware <2.21
- SICK RFU630-04100S01 with Firmware <2.21
- SICK RFU630-04101 with Firmware <2.21
- SICK RFU630-04102 with Firmware <2.21
- SICK RFU630-04103 with Firmware <2.21
- SICK RFU630-04104 with Firmware <2.21
- SICK RFU630-04105 with Firmware <2.21
- SICK RFU630-04106 with Firmware <2.21
- SICK RFU630-04108 with Firmware <2.21
- SICK RFU630-04109 with Firmware <2.21
- SICK RFU630-04117 with Firmware <2.21
- SICK RFU630-13100 with Firmware <2.21
- Summary
- Use of a Broken or Risky Cryptographic Algorithm in SICK RFU63x firmware version < v2.21 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encryption via the SSH interface.
- Remediation
- The patch and installation procedure for the firmware update is available from the responsible SICK customer contact person.
