CVE-2024-10772
Since the firmware update is not validated, an attacker can install modified firmware on the device. This has a high impact on the availabilty, integrity and confidentiality up to the complete compromise of the device.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.33%
- CWE
- CWE-649
- Published
- 2024-12-06
- Last modified
- 2026-03-13
Affected products
- SICK AG SICK InspectorP61x
- SICK AG SICK InspectorP62x
Weakness type
Related vulnerabilities
- CVE-2025-41351 — Weak encryption on Funambol's cloud server
- CVE-2025-5323 — fossasia open-event-server Mail Verification mail.py send_email_change_user_email reliance on obfuscation or encryption of security-relevant inputs without integrity checking
- CVE-2010-3300 — It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle...
- CVE-2019-3730 — RSA BSAFE Micro Edition Suite versions prior to 4.1.6.3 (in 4.1.x) and prior to 4.4 (in 4.2.x and...