{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-31409","assignerOrgId":"a6863dd2-93fc-443d-bef1-79f0b5020988","state":"PUBLISHED","assignerShortName":"SICK AG","dateReserved":"2023-04-27T18:35:47.418Z","datePublished":"2023-05-15T10:55:57.836Z","dateUpdated":"2025-01-23T17:32:30.188Z"},"containers":{"cna":{"affected":[{"defaultStatus":"affected","product":"SICK FTMG-ESD15AXX AIR FLOW SENSOR","vendor":"SICK AG","versions":[{"status":"affected","version":"all firmware versions"}]},{"defaultStatus":"affected","product":"SICK FTMG-ESD20AXX AIR FLOW SENSOR","vendor":"SICK AG","versions":[{"status":"affected","version":"all firmware versions"}]},{"defaultStatus":"affected","product":"SICK FTMG-ESD25AXX AIR FLOW SENSOR","vendor":"SICK AG","versions":[{"status":"affected","version":"all firmware versions"}]},{"defaultStatus":"affected","product":"SICK FTMG-ESN40SXX AIR FLOW SENSOR","vendor":"SICK AG","versions":[{"status":"affected","version":"all firmware versions"}]},{"defaultStatus":"affected","product":"SICK FTMG-ESN50SXX AIR FLOW SENSOR","vendor":"SICK AG","versions":[{"status":"affected","version":"all firmware versions"}]},{"defaultStatus":"affected","product":"SICK FTMG-ESR40SXX AIR FLOW SENSOR","vendor":"SICK AG","versions":[{"status":"affected","version":"all firmware versions"}]},{"defaultStatus":"affected","product":"SICK FTMG-ESR50SXX AIR FLOW SENSOR","vendor":"SICK AG","versions":[{"status":"affected","version":"all firmware versions"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":true,"type":"text/html","value":"\n\nUncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an remote attacker to influence the availability of the webserver by invocing a Slowloris style attack via HTTP requests.\n\n"}],"value":"\nUncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an remote attacker to influence the availability of the webserver by invocing a Slowloris style attack via HTTP requests.\n\n"}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-400","description":"CWE-400 Uncontrolled Resource Consumption","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"a6863dd2-93fc-443d-bef1-79f0b5020988","shortName":"SICK AG","dateUpdated":"2023-05-15T10:55:57.836Z"},"references":[{"tags":["issue-tracking"],"url":"https://sick.com/psirt"},{"tags":["vendor-advisory"],"url":"https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf"},{"tags":["x_csaf"],"url":"https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.json"}],"source":{"discovery":"INTERNAL"},"workarounds":[{"lang":"en","supportingMedia":[{"base64":true,"type":"text/html","value":"\n\nPlease make sure that you apply general security practices when operating the SICK FTMg\nlike network segmentation. The following General Security Practices and Operating Guidelines could\nmitigate the associated security risk."}],"value":"\nPlease make sure that you apply general security practices when operating the SICK FTMg\nlike network segmentation. The following General Security Practices and Operating Guidelines could\nmitigate the associated security risk."}],"x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T14:53:30.972Z"},"title":"CVE Program Container","references":[{"tags":["issue-tracking","x_transferred"],"url":"https://sick.com/psirt"},{"tags":["vendor-advisory","x_transferred"],"url":"https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.pdf"},{"tags":["x_csaf","x_transferred"],"url":"https://sick.com/.well-known/csaf/white/2023/sca-2023-0004.json"}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-01-23T17:32:25.090253Z","id":"CVE-2023-31409","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-01-23T17:32:30.188Z"}}]}}