CVE-2025-32470
Severity CVSS v4.0:
Pending analysis
Type:
CWE-284
Improper Access Control
Publication date:
28/04/2025
Last modified:
29/04/2025
Description
A remote unauthenticated attacker may be able to change the IP adress of the device, and therefore affecting the availability of the device.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF
- https://sick.com/psirt
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
- https://www.first.org/cvss/calculator/3.1
- https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0005.json
- https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0005.pdf



