The vendor explicitly identifies these products as affected by this CVE.
- SICK MEAC300 all versions with Firmware <4.0.54.21
- Summary
- The standard user uses the runas function to start the MEAC applications with administrative privileges. To ensure that the system can startup on its own, the credentials of the administrator were stored. Consequently, the EPC2 user can execute any command with administrative privileges. This allows a privilege escalation to the administrative level.
- Remediation
- Users are strongly recommended to upgrade to the latest release of the MEAC300 (>=4.0.54.21) that includes a patch for the vulnerability.
