Home
MEDIUM: 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NDefault status
affected
vers:all/* (custom)
affected
Description
All communication between the VNC server and client(s) is unencrypted. This allows an attacker to intercept the traffic and obtain sensitive data.
Problem types
CWE-319 Cleartext Transmission of Sensitive Information
Product status
vers:all/* (custom)
References
www.cisa.gov/...es-tools/resources/ics-recommended-practices
www.first.org/cvss/calculator/3.1
www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.json
sick.com/psirt
www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.pdf