The vendor explicitly identifies these products as affected by this CVE.
- SICK Enterprise Analytics all versions
- Summary
- The application provides access to a login protected H2 database for caching purposes. The username is prefilled.
- Remediation
- Please make sure that only trusted entities have access to the device. Furthermore, you should apply the following General Security Measures when operating the product to mitigate the associated security risk. The collected resources ”SICK Operating Guidelines” and ”ICS-CERT recommended practices on Industrial Security” could help to implement the general security practices.
