CVE-2025-27593 Information
Mar 15, 2025
cve
Description
The product can be used to distribute malicious code using SDD Device Drivers due to missing download verification checks leading to code execution on target systems.
Reference
https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF https://github.security.telekom.com/2025/03/multiple-vulnerabilities-in-sick-dl100.html https://sick.com/psirt https://www.cisa.gov/resources-tools/resources/ics-recommended-practices https://www.first.org/cvss/calculator/3.1 https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0004.json https://www.sick.com/.well-known/csaf/white/2025/sca-2025-0004.pdf
Share on: