SICK DL100 Unencrypted Transmission Vulnerability Allowing Pass-the-Hash Authentication

Vulnerability

A vulnerability exists in the SICK DL100-2xxxxxxx series, all firmware versions, due to the use of an unencrypted, proprietary communication protocol. This protocol transmits configuration data and handles device authentication. As a result, an attacker could intercept the authentication hash and exploit it to gain unauthorized access to the device using a pass-the-hash technique.

Impact

Exploitation of this vulnerability allows for unauthorized access to the device through intercepted authentication hashes, which can be used to bypass normal authentication mechanisms.

Remediation

SICK recommends applying general security practices when operating the DL100 devices. This includes minimizing network exposure, restricting network access, and following the SICK Operating Guidelines for Cybersecurity. These measures can help mitigate the associated security risks.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.