CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

sick

icr890-4_firmware

8 known vulnerabilities · sorted by CVSS score

CVE-2023-3270
HIGH8.6

Exposure of Sensitive Information to an Unauthorized Actor in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the system.

sick / icr890-4_firmware
Network
Published Jul 10, 2023
CVE-2023-3271
HIGH8.2

Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to gather information about the system and download data via the REST API by accessing unauthenticated endpoints.

sick / icr890-4_firmware
Network
Published Jul 10, 2023
CVE-2023-3272
HIGH7.5

Cleartext Transmission of Sensitive Information in the SICK ICR890-4 could allow a remote attacker to gather sensitive information by intercepting network traffic that is not encrypted.

sick / icr890-4_firmware
Network
Published Jul 10, 2023
CVE-2023-35696
HIGH7.5

Unauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the device via HTTP requests.

sick / icr890-4_firmware
Network
Published Jul 10, 2023
CVE-2023-3273
HIGH7.5

Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by changing settings of the device such as the IP address based on missing access control.

sick / icr890-4_firmware
Network
Published Jul 10, 2023
CVE-2023-35697
MEDIUM5.3

Improper Restriction of Excessive Authentication Attempts in the SICK ICR890-4 could allow a remote attacker to brute-force user credentials.

sick / icr890-4_firmware
Network
Published Jul 10, 2023
CVE-2023-35699
MEDIUM5.3

Cleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device to disclose sensitive information by accessing a SD card.

sick / icr890-4_firmware
Physical
Published Jul 10, 2023
CVE-2023-35698
MEDIUM5.3

Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the FTP server from the response given during a failed login attempt.

sick / icr890-4_firmware
Network
Published Jul 10, 2023