The vendor explicitly identifies these products as affected by this CVE.
- SICK InspectorP8xx firmware versions <3.11.1
- SICK Lector8xx firmware versions <2.4.0
- Summary
- The vulnerability may allow a remote low priviledged attacker to run arbitrary shell commands by using lower-level functions to interact with the device.
- Remediation
- Users are strongly recommended to upgrade to the latest release of the Lector8xx (>=2.4.0) and the InspectorP8xx (>=3.11.1) respectively that includes a patch for the vulnerability. It is also recommended to set a secure password, please refer to the respective operating instructions, linked in the reference section.
