Dismissed
(no matching packages found)
Permalink
CVE-2026-11841
9.4 CRITICAL
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): Low (L)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): Low (L)
Activity log
- Created & dismissed (no matching packages found) suggestion
CVE-2026-11841
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment.
References
-
https://www.sick.com/psirt x_SICK PSIRT Security Advisories
-
https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_gui… x_SICK Operating Guidelines
-
https://www.cisa.gov/resources-tools/resources/ics-recommended-practices x_ICS-CERT recommended practices on Industrial Security
-
https://www.first.org/cvss/calculator/3.1 x_CVSS v3.1 Calculator
-
https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0010.json x_The canonical URL.
Affected products
InspectorP61x
- <5.4.0
InspectorP62x
- <5.4.0
InspectorP63x
- ==all versions
InspectorP64x
- ==all versions
InspectorP65x
- ==all versions