- Products & ServicesProducts & Services
- SolutionsSolutions
- PricingPricing
- CompanyCompany
- ResourcesResources
en
en
Severity across 98 analyzed records
As of 09/11/2026, SICK AG recorded 2 security vulnerabilities in the last 90 days across 7 products, including 2 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, ICR890-4 had the most security vulnerabilities in the SICK AG ecosystem, with 1 vulnerabilities—approximately 50% of the provider's total vulnerabilities during this period.
| CVE | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-80469CVE-2026-80469 | Exploitation statusNot confirmed | FixYes | Affected productSentio Creator Extension 'Device Manager' | Published09/11/2026 | SeverityHigh |
CVE-2026-11841CVE-2026-11841 | Exploitation statusNot known exploited | FixYes | Affected productInspectorP61x | Published07/28/2026 | SeverityCritical |
CVE-2026-2331CVE-2026-2331 | Exploitation statusNot known exploited | FixYes | Affected productSICK Lector85x | Published03/06/2026 | SeverityCritical |
CVE-2026-2330CVE-2026-2330 | Exploitation statusNot known exploited | FixYes | Affected productSICK Lector85x | Published03/06/2026 | SeverityCritical |
CVE-2026-1627CVE-2026-1627 | Exploitation statusNot known exploited | FixYes | Affected productSICK LMS1000 | Published02/27/2026 | SeverityMedium |
CVE-2026-1626CVE-2026-1626 | Exploitation statusNot known exploited | FixYes | Affected productSICK LMS1000 | Published02/27/2026 | SeverityMedium |
CVE-2026-22646CVE-2026-22646 | Exploitation statusNot known exploited | FixYes | Affected productIncoming Goods Suite | Published01/15/2026 | SeverityMedium |
CVE-2026-22645CVE-2026-22645 | Exploitation statusNot known exploited | FixYes | Affected productIncoming Goods Suite | Published01/15/2026 | SeverityMedium |
CVE-2026-22644CVE-2026-22644 | Exploitation statusNot known exploited | FixNot confirmed | Affected productIncoming Goods Suite | Published01/15/2026 | SeverityMedium |
CVE-2026-22643CVE-2026-22643 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published01/15/2026 | SeverityUnknown |
CVE-2026-22642CVE-2026-22642 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published01/15/2026 | SeverityUnknown |
CVE-2026-22641CVE-2026-22641 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published01/15/2026 | SeverityUnknown |
CVE-2026-22640CVE-2026-22640 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published01/15/2026 | SeverityUnknown |
CVE-2026-22639CVE-2026-22639 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published01/15/2026 | SeverityUnknown |
CVE-2026-22638CVE-2026-22638 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published01/15/2026 | SeverityUnknown |
CVE-2026-22637CVE-2026-22637 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published01/15/2026 | SeverityUnknown |
CVE-2026-0713CVE-2026-0713 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published01/15/2026 | SeverityUnknown |
CVE-2026-0712CVE-2026-0712 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published01/15/2026 | SeverityUnknown |
CVE-2026-22920CVE-2026-22920 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published01/15/2026 | SeverityUnknown |
CVE-2026-22919CVE-2026-22919 | Exploitation statusNot known exploited | FixYes | Affected productTDC-X401GL | Published01/15/2026 | SeverityLow |
CVE-2026-22918CVE-2026-22918 | Exploitation statusNot known exploited | FixNot confirmed | Affected productTDC-X401GL | Published01/15/2026 | SeverityMedium |
CVE-2026-22917CVE-2026-22917 | Exploitation statusNot known exploited | FixYes | Affected productTDC-X401GL | Published01/15/2026 | SeverityMedium |
CVE-2026-22916CVE-2026-22916 | Exploitation statusNot known exploited | FixNot confirmed | Affected productTDC-X401GL | Published01/15/2026 | SeverityMedium |
CVE-2026-22915CVE-2026-22915 | Exploitation statusNot known exploited | FixNot confirmed | Affected productTDC-X401GL | Published01/15/2026 | SeverityMedium |
CVE-2026-22914CVE-2026-22914 | Exploitation statusNot known exploited | FixNot confirmed | Affected productTDC-X401GL | Published01/15/2026 | SeverityMedium |
CVE-2026-22913CVE-2026-22913 | Exploitation statusNot known exploited | FixYes | Affected productTDC-X401GL | Published01/15/2026 | SeverityMedium |
CVE-2026-22912CVE-2026-22912 | Exploitation statusNot known exploited | FixYes | Affected productTDC-X401GL | Published01/15/2026 | SeverityMedium |
CVE-2026-22911CVE-2026-22911 | Exploitation statusNot known exploited | FixNot confirmed | Affected productTDC-X401GL | Published01/15/2026 | SeverityMedium |
CVE-2026-22910CVE-2026-22910 | Exploitation statusNot known exploited | FixNot confirmed | Affected productTDC-X401GL | Published01/15/2026 | SeverityHigh |
CVE-2026-22909CVE-2026-22909 | Exploitation statusNot known exploited | FixNot confirmed | Affected productTDC-X401GL | Published01/15/2026 | SeverityHigh |
CVE-2026-22908CVE-2026-22908 | Exploitation statusNot known exploited | FixYes | Affected productTDC-X401GL | Published01/15/2026 | SeverityCritical |
CVE-2026-22907CVE-2026-22907 | Exploitation statusNot known exploited | FixYes | Affected productTDC-X401GL | Published01/15/2026 | SeverityCritical |
CVE-2025-59463Denial-of-service (DoS) via chunk size mismatch | Exploitation statusNot known exploited | FixNot confirmed | Affected productTLOC100-100 all Firmware versions | Published10/27/2025 | SeverityMedium |
CVE-2025-59462Denial-of-service (DoS) via delayed or missing client response | Exploitation statusNot known exploited | FixNot confirmed | Affected productTLOC100-100 all Firmware versions | Published10/27/2025 | SeverityMedium |
CVE-2025-59461API does not require authentication | Exploitation statusNot known exploited | FixNot confirmed | Affected productTLOC100-100 all Firmware versions | Published10/27/2025 | SeverityHigh |
CVE-2025-59460Unsecure access configuration | Exploitation statusNot known exploited | FixYes | Affected productTLOC100-100 with Firmware <7.1.1 | Published10/27/2025 | SeverityHigh |
CVE-2025-59459Denial-of-service (DoS) via resource consumption | Exploitation statusNot known exploited | FixYes | Affected productTLOC100-100 | Published10/27/2025 | SeverityMedium |
CVE-2025-58579Username Disclosure Through Missing Authentication | Exploitation statusNot known exploited | FixYes | Affected productBaggage Analytics | Published10/06/2025 | SeverityMedium |
CVE-2025-58591Path Traversal | Exploitation statusNot known exploited | FixYes | Affected productBaggage Analytics | Published10/06/2025 | SeverityMedium |
CVE-2025-58590Path traversal | Exploitation statusNot known exploited | FixYes | Affected productBaggage Analytics | Published10/06/2025 | SeverityMedium |
CVE-2025-58589Information Disclosure Through Stacktrace | Exploitation statusNot known exploited | FixYes | Affected productBaggage Analytics | Published10/06/2025 | SeverityLow |
CVE-2025-58587Improper Restriction of Excessive Authentication Attempts | Exploitation statusNot known exploited | FixYes | Affected productBaggage Analytics | Published10/06/2025 | SeverityMedium |
CVE-2025-58586User Enumeration by excessive error output | Exploitation statusNot known exploited | FixYes | Affected productBaggage Analytics | Published10/06/2025 | SeverityMedium |
CVE-2025-58585Sensitive Information Disclosure Through Missing Authentication | Exploitation statusNot known exploited | FixYes | Affected productBaggage Analytics | Published10/06/2025 | SeverityMedium |
CVE-2025-58584Plain Text Transmission of Username and Password in the URL | Exploitation statusNot known exploited | FixYes | Affected productBaggage Analytics | Published10/06/2025 | SeverityMedium |
CVE-2025-58583User Enumeration | Exploitation statusNot known exploited | FixNot confirmed | Affected productEnterprise Analytics | Published10/06/2025 | SeverityMedium |
CVE-2025-58582Uncontrolled Resource Consumption via log file | Exploitation statusNot known exploited | FixNot confirmed | Affected productEnterprise Analytics | Published10/06/2025 | SeverityMedium |
CVE-2025-58581Information Disclosure Through Stacktrace-/MQTT/Config/changeAll | Exploitation statusNot known exploited | FixNot confirmed | Affected productEnterprise Analytics | Published10/06/2025 | SeverityMedium |
CVE-2025-58580Injection via log file | Exploitation statusNot known exploited | FixNot confirmed | Affected productEnterprise Analytics | Published10/06/2025 | SeverityMedium |
CVE-2025-58578Unlimited user creation by authorized users | Exploitation statusNot known exploited | FixNot confirmed | Affected productEnterprise Analytics | Published10/06/2025 | SeverityLow |
CVE-2025-9914CVE-2025-9914 | Exploitation statusNot known exploited | FixYes | Affected productBaggage Analytics | Published10/06/2025 | SeverityMedium |
CVE-2025-9913Cross Site Scripting: Session Hijacking | Exploitation statusNot known exploited | FixYes | Affected productBaggage Analytics | Published10/06/2025 | SeverityMedium |
CVE-2025-49200Unencrypted backup contains sensitive information | Exploitation statusNot known exploited | FixNot confirmed | Affected productSICK Field Analytics | Published06/12/2025 | SeverityMedium |
CVE-2025-49199Backup files can be modified and uploaded | Exploitation statusNot known exploited | FixNot confirmed | Affected productSICK Field Analytics | Published06/12/2025 | SeverityHigh |
CVE-2025-49198Poor quality of randomness in authorization tokens | Exploitation statusNot known exploited | FixNot confirmed | Affected productSICK Media Server | Published06/12/2025 | SeverityLow |
CVE-2025-49197Deprecated TLS version supported | Exploitation statusNot known exploited | FixYes | Affected productSICK Media Server | Published06/12/2025 | SeverityMedium |
CVE-2025-49196Deprecated TLS version supported | Exploitation statusNot known exploited | FixNot confirmed | Affected productSICK Field Analytics | Published06/12/2025 | SeverityMedium |
CVE-2025-49195No protection against brute-force attacks | Exploitation statusNot known exploited | FixNot confirmed | Affected productSICK Media Server | Published06/12/2025 | SeverityMedium |
CVE-2025-49194Unencrypted communication | Exploitation statusNot known exploited | FixNot confirmed | Affected productSICK Media Server | Published06/12/2025 | SeverityHigh |
CVE-2025-49193Missing HTTP Security Headers | Exploitation statusNot known exploited | FixYes | Affected productField Analytics | Published06/12/2025 | SeverityMedium |
CVE-2025-49192Clickjacking | Exploitation statusNot known exploited | FixYes | Affected productSICK Field Analytics | Published06/12/2025 | SeverityMedium |
CVE-2025-49191Dashboards and iFrames can link malicious web content | Exploitation statusNot known exploited | FixNot confirmed | Affected productSICK Field Analytics | Published06/12/2025 | SeverityMedium |
CVE-2025-49190Server-Side Request Forgery | Exploitation statusNot known exploited | FixNot confirmed | Affected productSICK Field Analytics | Published06/12/2025 | SeverityMedium |
CVE-2025-49189Cookie missing HttpOnly flag | Exploitation statusNot known exploited | FixYes | Affected productSICK Media Server | Published06/12/2025 | SeverityMedium |
CVE-2025-49188Sensitive Data in URL | Exploitation statusNot known exploited | FixNot confirmed | Affected productSICK Field Analytics | Published06/12/2025 | SeverityMedium |
CVE-2025-49187User enumeration | Exploitation statusNot known exploited | FixNot confirmed | Affected productSICK Field Analytics | Published06/12/2025 | SeverityMedium |
CVE-2025-49186No brute-force protection | Exploitation statusNot known exploited | FixYes | Affected productField Analytics | Published06/12/2025 | SeverityMedium |
CVE-2025-49185Stored Cross-Site-Script | Exploitation statusNot known exploited | FixNot confirmed | Affected productSICK Field Analytics | Published06/12/2025 | SeverityMedium |
CVE-2025-49184Information disclosure to unauthorized user | Exploitation statusNot known exploited | FixNot confirmed | Affected productField Analytics | Published06/12/2025 | SeverityHigh |
CVE-2025-49183Unencrypted communication (HTTP) | Exploitation statusNot known exploited | FixNot confirmed | Affected productSICK Media Server | Published06/12/2025 | SeverityHigh |
CVE-2025-49182Credential disclosure | Exploitation statusNot known exploited | FixYes | Affected productSICK Media Server | Published06/12/2025 | SeverityHigh |
CVE-2025-49181Configurations endpoint does not require authorization | Exploitation statusNot known exploited | FixNot confirmed | Affected productSICK Media Server | Published06/12/2025 | SeverityHigh |
CVE-2025-32472DoS attack by conducting a slowloris-type attack | Exploitation statusNot known exploited | FixNot confirmed | Affected productSICK multiScan1XX | Published04/28/2025 | SeverityMedium |
CVE-2025-32471Reuse of salt | Exploitation statusNot known exploited | FixNot confirmed | Affected productSICK FLX3-CPUC200 | Published04/28/2025 | SeverityLow |
CVE-2025-32470Unauthenticated change of IP adress | Exploitation statusNot known exploited | FixNot confirmed | Affected productSICK FLX0-GPNT100 | Published04/28/2025 | SeverityHigh |
CVE-2025-27595Weak hashing alghrythm | Exploitation statusNot known exploited | FixNot confirmed | Affected productSICK DL100-2xxxxxxx | Published03/14/2025 | SeverityCritical |
CVE-2025-27594Unencrypted transmission of password hash | Exploitation statusNot known exploited | FixNot confirmed | Affected productSICK DL100-2xxxxxxx | Published03/14/2025 | SeverityHigh |
CVE-2025-27593RCE due to Device Driver | Exploitation statusNot known exploited | FixNot confirmed | Affected productSICK DL100-2xxxxxxx | Published03/14/2025 | SeverityCritical |
CVE-2025-0593SICK Lector8xx and InspectorP8xx vulnerable for code execution | Exploitation statusNot known exploited | FixYes | Affected productSICK Lector8xx | Published02/14/2025 | SeverityHigh |
CVE-2025-0592SICK Lector8xx and InspectorP8xx vulnerable for code execution | Exploitation statusNot known exploited | FixYes | Affected productSICK Lector8xx | Published02/14/2025 | SeverityHigh |
CVE-2025-0867Privilege Escalation in MEAC300 | Exploitation statusNot known exploited | FixYes | Affected productSICK MEAC300 | Published02/14/2025 | SeverityCritical |
CVE-2024-10776SICK InspectorP61x and SICK InspectorP62x: missing authentication | Exploitation statusNot known exploited | FixYes | Affected productSICK InspectorP61x | Published12/06/2024 | SeverityHigh |
CVE-2024-10774SICK InspectorP61x and SICK InspectorP62x have unauthenticated CROWN APIs | Exploitation statusNot known exploited | FixYes | Affected productSICK InspectorP61x | Published12/06/2024 | SeverityHigh |
CVE-2024-10773SICK InspectorP61x, SICK InspectorP62x and SICK TiM3xx are vulnerable for pass-the-hash attacks | Exploitation statusNot known exploited | FixYes | Affected productSICK InspectorP61x | Published12/06/2024 | SeverityCritical |
CVE-2024-10772SICK InspectorP61x and SICK InspectorP62x are vulnerable for firmware modification | Exploitation statusNot known exploited | FixYes | Affected productSICK InspectorP61x | Published12/06/2024 | SeverityHigh |
CVE-2024-10771SICK InspectorP61x, SICK InspectorP62x and SICK TiM3xx are vulnerable for remote code execution | Exploitation statusNot known exploited | FixYes | Affected productSICK InspectorP61x | Published12/06/2024 | SeverityHigh |
CVE-2024-11022SICK InspectorP61x and SICK InspectorP62x are vulnerable for a replay attack | Exploitation statusNot known exploited | FixNot confirmed | Affected productSICK InspectorP61x | Published12/06/2024 | SeverityMedium |
CVE-2024-11075SICK Incoming Goods Suite privilege escalation vulnerability | Exploitation statusNot known exploited | FixYes | Affected productSICK Incoming Goods Suite | Published11/19/2024 | SeverityHigh |
CVE-2024-10025Vulnerability in SICK CLV6xx, SICK Lector6xx and SICK RFx6xx | Exploitation statusNot known exploited | FixYes | Affected productSICK CLV6xx | Published10/17/2024 | SeverityCritical |
CVE-2024-8751CVE-2024-8751 | Exploitation statusNot known exploited | FixYes | Affected productMSC800 | Published09/12/2024 | SeverityHigh |
CVE-2023-5246CVE-2023-5246 | Exploitation statusNot known exploited | FixNot confirmed | Affected productFX0-GMOD00000 | Published10/23/2023 | SeverityHigh |
CVE-2023-5103CVE-2023-5103 | Exploitation statusNot known exploited | FixYes | Affected productAPU0200 | Published10/09/2023 | SeverityMedium |
CVE-2023-5102CVE-2023-5102 | Exploitation statusNot known exploited | FixYes | Affected productAPU0200 | Published10/09/2023 | SeverityMedium |
CVE-2023-5101CVE-2023-5101 | Exploitation statusNot known exploited | FixYes | Affected productAPU0200 | Published10/09/2023 | SeverityMedium |
CVE-2023-5100CVE-2023-5100 | Exploitation statusNot known exploited | FixYes | Affected productAPU0200 | Published10/09/2023 | SeverityMedium |
CVE-2023-43697CVE-2023-43697 | Exploitation statusNot known exploited | FixYes | Affected productAPU0200 | Published10/09/2023 | SeverityMedium |
CVE-2023-43698CVE-2023-43698 | Exploitation statusNot known exploited | FixYes | Affected productAPU0200 | Published10/09/2023 | SeverityHigh |
CVE-2023-43699CVE-2023-43699 | Exploitation statusNot known exploited | FixYes | Affected productAPU0200 | Published10/09/2023 | SeverityHigh |
CVE-2023-43700CVE-2023-43700 | Exploitation statusNot known exploited | FixYes | Affected productAPU0200 | Published10/09/2023 | SeverityHigh |
CVE-2023-43696CVE-2023-43696 | Exploitation statusNot known exploited | FixYes | Affected productAPU0200 | Published10/09/2023 | SeverityHigh |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan