The vendor explicitly identifies these products as affected by this CVE.
- SICK FTMG-ESD15AXX AIR FLOW SENSOR all versions with Firmware <v2.x
- SICK FTMG-ESD20AXX AIR FLOW SENSOR all versions with Firmware <v2.x
- SICK FTMG-ESD25AXX AIR FLOW SENSOR all versions with Firmware <v2.x
- SICK FTMG-ESR40SXX AIR FLOW SENSOR all versions with Firmware <v2.x
- SICK FTMG-ESR50SXX AIR FLOW SENSOR all versions with Firmware <v2.x
- SICK FTMG-ESN40SXX AIR FLOW SENSOR all versions with Firmware <v2.x
- SICK FTMG-ESN50SXX AIR FLOW SENSOR all versions with Firmware <v2.x
- Summary
- Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis of source code.
- Remediation
- Please make sure that you apply general security practices when operating the SICK FTMg like network segmentation. The following General Security Practices and Operating Guidelines could mitigate the associated security risk.
