{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-2330",
        "assignerOrgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
        "state": "PUBLISHED",
        "assignerShortName": "SICK AG",
        "dateReserved": "2026-02-11T09:33:15.947Z",
        "datePublished": "2026-03-06T07:54:45.958Z",
        "dateUpdated": "2026-03-09T21:04:31.663Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "affected",
                    "product": "SICK Lector85x",
                    "vendor": "SICK AG",
                    "versions": [
                        {
                            "lessThan": "2.8.0",
                            "status": "affected",
                            "version": "0",
                            "versionType": "custom"
                        }
                    ]
                },
                {
                    "defaultStatus": "affected",
                    "product": "SICK Lector83x",
                    "vendor": "SICK AG",
                    "versions": [
                        {
                            "lessThan": "2.8.0",
                            "status": "affected",
                            "version": "0",
                            "versionType": "custom"
                        }
                    ]
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "<p>An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain directories intended for internal testing were not covered by the whitelist and are accessible without authentication. An unauthenticated attacker could place a manipulated parameter file that becomes active after a reboot, allowing modification of critical device settings, including network configuration and application parameters.</p>"
                        }
                    ],
                    "value": "An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain directories intended for internal testing were not covered by the whitelist and are accessible without authentication. An unauthenticated attacker could place a manipulated parameter file that becomes active after a reboot, allowing modification of critical device settings, including network configuration and application parameters."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "attackComplexity": "LOW",
                        "attackVector": "NETWORK",
                        "availabilityImpact": "HIGH",
                        "baseScore": 9.4,
                        "baseSeverity": "CRITICAL",
                        "confidentialityImpact": "LOW",
                        "environmentalScore": 9.4,
                        "environmentalSeverity": "CRITICAL",
                        "integrityImpact": "HIGH",
                        "privilegesRequired": "NONE",
                        "scope": "UNCHANGED",
                        "temporalScore": 9.4,
                        "temporalSeverity": "CRITICAL",
                        "userInteraction": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H",
                        "version": "3.1"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-552",
                            "description": "CWE-552 Files or Directories Accessible to External Parties",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "a6863dd2-93fc-443d-bef1-79f0b5020988",
                "shortName": "SICK AG",
                "dateUpdated": "2026-03-06T07:54:45.958Z"
            },
            "references": [
                {
                    "tags": [
                        "x_SICK PSIRT Security Advisories"
                    ],
                    "url": "https://www.sick.com/psirt"
                },
                {
                    "tags": [
                        "x_SICK Operating Guidelines"
                    ],
                    "url": "https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf"
                },
                {
                    "tags": [
                        "x_ICS-CERT recommended practices on Industrial Security"
                    ],
                    "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices"
                },
                {
                    "tags": [
                        "x_CVSS v3.1 Calculator"
                    ],
                    "url": "https://www.first.org/cvss/calculator/3.1"
                },
                {
                    "tags": [
                        "x_The canonical URL."
                    ],
                    "url": "https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0006.json"
                },
                {
                    "tags": [
                        "vendor-advisory"
                    ],
                    "url": "https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0006.pdf"
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "<p>Users are strongly recommended to upgrade to release version 2.8.0.</p>"
                        }
                    ],
                    "value": "Users are strongly recommended to upgrade to release version 2.8.0."
                }
            ],
            "source": {
                "advisory": "SCA-2026-0006",
                "discovery": "INTERNAL"
            },
            "title": "CVE-2026-2330",
            "x_generator": {
                "engine": "csaf2cve 0.2.1"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "id": "CVE-2026-2330",
                                "role": "CISA Coordinator",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "version": "2.0.3",
                                "timestamp": "2026-03-09T20:56:25.769774Z"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-03-09T21:04:31.663Z"
                }
            }
        ]
    }
}