CVE-2026-11841
CRITICAL
9.4
CVSS 3.1
Description
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment.
Metadata
Severity & Metrics
9.4
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
SSVC — CISA Coordinator
Affected products (5)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| SICK AG | InspectorP61x | — | 0 < 5.4.0 |
| SICK AG | InspectorP62x | — | 0 < 5.4.0 |
| SICK AG | InspectorP63x | — | all versions |
| SICK AG | InspectorP64x | — | all versions |
| SICK AG | InspectorP65x | — | all versions |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-552 | cna | CWE-552 Files or directories accessible to external parties |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 9.4 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
References (6)
- https://www.sick.com/psirt
- https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
- https://www.first.org/cvss/calculator/3.1
- https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0010.json
- https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0010.pdf