CVE-2025-27593 Information

Description

The product can be used to distribute malicious code using SDD Device Drivers due to missing download verification checks leading to code execution on target systems.

Reference

https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF https://github.security.telekom.com/2025/03/multiple-vulnerabilities-in-sick-dl100.html https://sick.com/psirt https://www.cisa.gov/resources-tools/resources/ics-recommended-practices https://www.first.org/cvss/calculator/3.1 https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0004.json https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0004.pdf

Share on: