SICK InspectorP61x and SICK InspectorP62x are vulnerable for firmware modification
Vulnerability Description
Since the firmware update is not validated, an attacker can install modified firmware on the device. This has a high impact on the availabilty, integrity and confidentiality up to the complete compromise of the device.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-10772
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Manuel Stotz
- Tobias Jaeger
References
- https://sick.com/psirt
- https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
- https://www.first.org/cvss/calculator/3.1
- https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.pdf
- https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.json
More from SICK AG
View All →Affected Vendor
SICK AG
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.