The vendor explicitly identifies these products as affected by this CVE.
- SICK FTMG-ESD15AXX AIR FLOW SENSOR all versions with Firmware <v2.x
- SICK FTMG-ESD20AXX AIR FLOW SENSOR all versions with Firmware <v2.x
- SICK FTMG-ESD25AXX AIR FLOW SENSOR all versions with Firmware <v2.x
- SICK FTMG-ESR40SXX AIR FLOW SENSOR all versions with Firmware <v2.x
- SICK FTMG-ESR50SXX AIR FLOW SENSOR all versions with Firmware <v2.x
- SICK FTMG-ESN40SXX AIR FLOW SENSOR all versions with Firmware <v2.x
- SICK FTMG-ESN50SXX AIR FLOW SENSOR all versions with Firmware <v2.x
- Summary
- Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to influence the availability of the webserver by invocing several open file requests via the REST interface.
- Remediation
- SICK has released a new major version v3.0.0.131.Release of the SICK FTMg firmware and recommends updating to the newest version.
